Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

641 advisories

Loading
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an... Critical Unreviewed
CVE-2026-104075 was published Oct 8, 2026
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions. High Unreviewed
CVE-2026-39793 was published Oct 6, 2026
Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions. High Unreviewed
CVE-2026-39769 was published Oct 6, 2026
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions. Moderate Unreviewed
CVE-2026-100518 was published Oct 6, 2026
vvvvvvvvvvitel Credited to vvvvvvvvvvitel, mcollina, UlisesGascon, schecthellraiser606, and B1gN0Se mcollina mcollina
UlisesGascon UlisesGascon schecthellraiser606 schecthellraiser606 B1gN0Se B1gN0Se
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets High
GHSA-9c5c-9qcx-q35q was published for @nestjs/platform-fastify (npm) Sep 30, 2026
zerovulnlabs Credited to zerovulnlabs
Snipe-IT: 2FA bypass via the API token flow High
CVE-2026-63493 was published for snipe/snipe-it (Composer) Sep 24, 2026
colinthebomb1 Credited to colinthebomb1
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` High
CVE-2026-58269 was published for @sync-in/server (npm) Sep 22, 2026
SakusenSec Credited to SakusenSec and johaven johaven johaven
Steeltoe: Header-forwarded client cert lacks proof of private-key possession Moderate
CVE-2026-81868 was published for Steeltoe.Security.Authorization.Certificate (NuGet) Sep 17, 2026
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. Critical Unreviewed
CVE-2026-62101 was published Sep 17, 2026
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the... High Unreviewed
CVE-2026-14917 was published Sep 16, 2026
ProTip! Advisories are also available from the GraphQL API