GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
641 advisories
Filter by severity
Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery...
High
Unreviewed
CVE-2026-93949
was published
Oct 10, 2026
A malicious user with physical access to the device can boot the switch from factory settings...
Moderate
Unreviewed
CVE-2026-33272
was published
Oct 9, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack...
Moderate
Unreviewed
CVE-2026-106601
was published
Oct 9, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack...
Moderate
Unreviewed
CVE-2026-106602
was published
Oct 9, 2026
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an...
Critical
Unreviewed
CVE-2026-104075
was published
Oct 8, 2026
The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing...
Moderate
Unreviewed
CVE-2026-107361
was published
Oct 8, 2026
An authentication bypass vulnerability exists in the web management interface of Brocade Fabric...
High
Unreviewed
CVE-2026-94585
was published
Oct 8, 2026
Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type...
Critical
Unreviewed
CVE-2026-107194
was published
Oct 7, 2026
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability...
Critical
Unreviewed
CVE-2026-19572
was published
Oct 7, 2026
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
High
Unreviewed
CVE-2026-39793
was published
Oct 6, 2026
Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
High
Unreviewed
CVE-2026-39769
was published
Oct 6, 2026
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
Moderate
Unreviewed
CVE-2026-100518
was published
Oct 6, 2026
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
High
CVE-2026-76169
was published
for
fastify
(npm)
Sep 30, 2026
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible...
Moderate
Unreviewed
CVE-2026-100261
was published
Sep 30, 2026
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
High
GHSA-9c5c-9qcx-q35q
was published
for
@nestjs/platform-fastify
(npm)
Sep 30, 2026
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its...
Moderate
Unreviewed
CVE-2026-88828
was published
Sep 28, 2026
Snipe-IT: 2FA bypass via the API token flow
High
CVE-2026-63493
was published
for
snipe/snipe-it
(Composer)
Sep 24, 2026
In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an...
Critical
Unreviewed
CVE-2026-90481
was published
Sep 24, 2026
Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server...
Moderate
Unreviewed
CVE-2026-79680
was published
Sep 24, 2026
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
High
CVE-2026-58269
was published
for
@sync-in/server
(npm)
Sep 22, 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi...
High
Unreviewed
CVE-2026-93928
was published
Sep 22, 2026
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
Moderate
CVE-2026-81868
was published
for
Steeltoe.Security.Authorization.Certificate
(NuGet)
Sep 17, 2026
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Critical
Unreviewed
CVE-2026-62101
was published
Sep 17, 2026
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the...
High
Unreviewed
CVE-2026-14917
was published
Sep 16, 2026
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log...
Critical
Unreviewed
CVE-2026-27546
was published
Sep 16, 2026
ProTip!
Advisories are also available from the
GraphQL API