GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
92 advisories
Filter by severity
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability...
High
Unreviewed
CVE-2026-92467
was published
Sep 16, 2026
pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password...
Critical
Unreviewed
CVE-2026-91995
was published
Sep 15, 2026
A security flaw has been discovered in sfturing hosp_order up to...
Moderate
Unreviewed
CVE-2026-86260
was published
Sep 7, 2026
phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerability in the user control...
High
Unreviewed
CVE-2026-85591
was published
Sep 4, 2026
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
High
CVE-2026-73292
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 3, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment
High
CVE-2026-54175
was published
for
backpack/crud
(Composer)
Aug 20, 2026
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow...
High
Unreviewed
CVE-2026-76633
was published
Aug 20, 2026
Nexus Repository 3 contained an endpoint used to change the administrator account password during...
Moderate
Unreviewed
CVE-2026-17599
was published
Aug 7, 2026
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via...
Critical
Unreviewed
CVE-2026-15964
was published
Aug 1, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows...
Critical
Unreviewed
CVE-2026-12692
was published
Jul 17, 2026
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change...
High
Unreviewed
CVE-2026-56305
was published
Jul 10, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
High
Unreviewed
CVE-2026-54801
was published
Jul 9, 2026
OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
High
CVE-2026-46623
was published
for
org.openidentityplatform.openam:openam-auth-oauth2
(Maven)
Jun 26, 2026
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user...
High
Unreviewed
CVE-2025-71328
was published
Jun 26, 2026
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change...
High
Unreviewed
CVE-2025-71337
was published
Jun 23, 2026
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password...
Critical
Unreviewed
CVE-2026-5386
was published
May 29, 2026
Unverified password change in Devolutions Server allows an attacker to change a user's password...
Low
Unreviewed
CVE-2026-9249
was published
May 26, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
CVE-2026-42084
was published
for
openc3
(RubyGems)
Apr 22, 2026
Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers...
Moderate
Unreviewed
CVE-2019-25653
was published
Mar 30, 2026
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset...
Critical
Unreviewed
CVE-2026-30458
was published
Mar 26, 2026
An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and...
Critical
Unreviewed
CVE-2025-70082
was published
Mar 11, 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication...
High
Unreviewed
CVE-2026-27757
was published
Feb 27, 2026
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the...
High
Unreviewed
CVE-2026-24443
was published
Feb 24, 2026
ProTip!
Advisories are also available from the
GraphQL API