GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
2,507 advisories
Filter by severity
The affected products are vulnerable to an authentication bypass that allows unauthenticated...
High
Unreviewed
CVE-2026-68953
was published
Sep 15, 2026
The affected products are missing authentication for a critical function, which could allow an...
High
Unreviewed
CVE-2026-68070
was published
Sep 15, 2026
miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an...
Moderate
Unreviewed
CVE-2026-89027
was published
Sep 15, 2026
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for...
High
Unreviewed
CVE-2026-81238
was published
Sep 15, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19...
Moderate
Unreviewed
CVE-2026-12910
was published
Sep 15, 2026
Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature,...
High
Unreviewed
CVE-2026-18111
was published
Sep 15, 2026
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing...
High
Unreviewed
CVE-2026-91996
was published
Sep 15, 2026
Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler ...
High
Unreviewed
CVE-2026-90896
was published
Sep 14, 2026
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another...
Moderate
Unreviewed
CVE-2026-12763
was published
Sep 14, 2026
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without...
High
Unreviewed
CVE-2026-90944
was published
Sep 14, 2026
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Critical
CVE-2026-59178
was published
for
esphome-device-builder
(pip)
Sep 14, 2026
LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket...
High
Unreviewed
CVE-2026-90938
was published
Sep 14, 2026
Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit ...
Moderate
Unreviewed
CVE-2026-82784
was published
Sep 14, 2026
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this...
High
Unreviewed
CVE-2026-82787
was published
Sep 14, 2026
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin...
Moderate
Unreviewed
CVE-2026-90543
was published
Sep 12, 2026
When a particular authentication mode is configured, the reverse proxy forwards requests for a...
Moderate
Unreviewed
CVE-2026-90449
was published
Sep 12, 2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
High
CVE-2026-59148
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
Critical
CVE-2026-59971
was published
for
mysql-mcp-server
(pip)
Sep 11, 2026
MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service...
Moderate
Unreviewed
CVE-2026-89261
was published
Sep 11, 2026
MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification...
Moderate
Unreviewed
CVE-2026-89263
was published
Sep 11, 2026
A vulnerability in the Chef Automate API gateway and identity validation path may allow an...
Critical
Unreviewed
CVE-2026-80462
was published
Sep 11, 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated...
High
Unreviewed
CVE-2026-89250
was published
Sep 11, 2026
WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing...
High
Unreviewed
CVE-2026-89176
was published
Sep 11, 2026
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
Critical
CVE-2026-88018
was published
for
github.com/rclone/rclone
(Go)
Sep 10, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by...
Moderate
Unreviewed
CVE-2026-9336
was published
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API