GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,683
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,532
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,684 advisories
Filter by severity
NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component,...
High
Unreviewed
CVE-2026-24170
was published
Aug 25, 2026
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the...
Moderate
Unreviewed
CVE-2026-78885
was published
Aug 25, 2026
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
High
CVE-2026-55533
was published
for
PraisonAI
(pip)
Aug 25, 2026
A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of...
Moderate
Unreviewed
CVE-2026-78863
was published
Aug 25, 2026
An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache...
High
Unreviewed
CVE-2026-53561
was published
Aug 25, 2026
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController:...
Moderate
Unreviewed
CVE-2026-78434
was published
Aug 25, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the...
Critical
Unreviewed
CVE-2026-78167
was published
Aug 24, 2026
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the...
High
Unreviewed
CVE-2026-78168
was published
Aug 24, 2026
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the...
Moderate
Unreviewed
CVE-2026-78154
was published
Aug 24, 2026
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was...
Critical
Unreviewed
CVE-2026-77000
was published
Aug 22, 2026
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side...
Critical
Unreviewed
CVE-2026-77002
was published
Aug 22, 2026
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does...
Critical
Unreviewed
CVE-2026-77001
was published
Aug 22, 2026
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in...
High
Unreviewed
CVE-2026-76793
was published
Aug 22, 2026
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to...
High
Unreviewed
CVE-2026-18052
was published
Aug 22, 2026
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier...
Moderate
Unreviewed
CVE-2025-15671
was published
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-17142
was published
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2026-16972
was published
Aug 21, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2026-17000
was published
Aug 21, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
Critical
CVE-2026-55445
was published
for
@whyour/qinglong
(npm)
Aug 20, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user...
High
Unreviewed
CVE-2026-76338
was published
Aug 20, 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to manipulate network...
High
Unreviewed
CVE-2026-16857
was published
Aug 19, 2026
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Moderate
CVE-2026-55235
was published
for
langgraph-api
(pip)
Aug 19, 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure...
Critical
Unreviewed
CVE-2026-20317
was published
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API