GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,629
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,149
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
259 advisories
Filter by severity
When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation...
Moderate
Unreviewed
CVE-2026-12704
was published
Sep 2, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Moderate
CVE-2026-84306
was published
for
filament/filament
(Composer)
Sep 1, 2026
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp...
Moderate
Unreviewed
CVE-2026-82470
was published
Aug 29, 2026
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Moderate
Unreviewed
CVE-2026-82220
was published
Aug 28, 2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a...
High
Unreviewed
CVE-2025-61479
was published
Aug 26, 2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a...
High
Unreviewed
CVE-2025-61480
was published
Aug 26, 2026
Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability....
High
Unreviewed
CVE-2026-41707
was published
Aug 26, 2026
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If...
Critical
Unreviewed
CVE-2026-65905
was published
Aug 26, 2026
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to...
Critical
Unreviewed
CVE-2026-53424
was published
Aug 20, 2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to...
High
Unreviewed
CVE-2026-73136
was published
Aug 19, 2026
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to...
High
Unreviewed
CVE-2026-67581
was published
Aug 19, 2026
phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge...
Critical
Unreviewed
CVE-2026-76214
was published
Aug 19, 2026
http4k: `DigestAuthProvider.verify` did not bind to request URI
High
CVE-2026-54148
was published
for
org.http4k:http4k-security-digest
(Maven)
Aug 17, 2026
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows...
Critical
Unreviewed
CVE-2026-73683
was published
Aug 15, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized...
High
Unreviewed
CVE-2026-17045
was published
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security...
Moderate
Unreviewed
CVE-2026-17268
was published
Aug 12, 2026
Vulnerability-Lookup contains an
authentication weakness in its account activation and password...
High
Unreviewed
CVE-2026-73431
was published
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
High
CVE-2026-46369
was published
for
nimiq-blockchain
(Rust)
Aug 12, 2026
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized...
High
Unreviewed
CVE-2026-62911
was published
Aug 11, 2026
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion...
High
Unreviewed
CVE-2026-72780
was published
Aug 11, 2026
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Critical
GHSA-wg23-69c2-gjc8
was published
for
craftcms/cms
(Composer)
Aug 7, 2026
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed...
Critical
Unreviewed
CVE-2026-68079
was published
Aug 6, 2026
A flaw was found in the SAML broker component of Keycloak, an identity and access management...
Moderate
Unreviewed
CVE-2026-18967
was published
Aug 6, 2026
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse...
High
Unreviewed
CVE-2026-15614
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API