GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,912
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
735 advisories
Filter by severity
Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a...
Moderate
Unreviewed
CVE-2026-107336
was published
Oct 8, 2026
Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows...
High
Unreviewed
CVE-2026-107589
was published
Oct 8, 2026
A vulnerability has been identified regarding insufficient validation in the Frappe Cloud/ERPNext...
Moderate
Unreviewed
CVE-2026-4894
was published
Oct 8, 2026
An authentication bypass and command injection vulnerability exists in the inter-switch remote...
High
Unreviewed
CVE-2026-87663
was published
Oct 8, 2026
An authorization logic vulnerability exists in the Brocade Fabric OS versions before 10.0.1 REST...
Moderate
Unreviewed
CVE-2026-87670
was published
Oct 8, 2026
An authentication and access control bypass vulnerability exists in the web server management...
Moderate
Unreviewed
CVE-2026-87686
was published
Oct 8, 2026
Payload authentication token field handling issue
Critical
CVE-2026-105863
was published
for
payload
(npm)
Oct 7, 2026
Authenticated users are able to manipulate both the SMTP
envelope “Envelope-from” and “From”...
Moderate
Unreviewed
CVE-2026-33586
was published
Oct 7, 2026
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
High
CVE-2026-104891
was published
for
@insumermodel/mppx-condition-gate
(npm)
Oct 7, 2026
Langflow: IP Spoofing Bypass via `X-Forwarded-For` Allowing Remote Configuration Write
High
CVE-2026-105741
was published
for
langflow
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook lacks signature verification, allowing unauthenticated message injection and sender spoofing
High
CVE-2026-61428
was published
for
praisonai
(pip)
Oct 7, 2026
Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a...
Moderate
Unreviewed
CVE-2026-97146
was published
Oct 7, 2026
An unauthenticated attacker located on an adjacent private network (or any attacker routed...
High
Unreviewed
CVE-2026-102161
was published
Oct 6, 2026
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
Moderate
Unreviewed
CVE-2026-97308
was published
Oct 6, 2026
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
Moderate
Unreviewed
CVE-2026-39772
was published
Oct 6, 2026
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
Moderate
Unreviewed
CVE-2026-105057
was published
Oct 6, 2026
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
High
Unreviewed
CVE-2026-41558
was published
Oct 6, 2026
proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
Critical
CVE-2026-90711
was published
for
proxy-addr
(npm)
Oct 5, 2026
Perforce P4 Search prior to 2026.4.2 trusts a client-supplied address when validating certain...
Moderate
Unreviewed
CVE-2026-103512
was published
Oct 5, 2026
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login...
Critical
Unreviewed
CVE-2026-105215
was published
Oct 4, 2026
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open...
High
Unreviewed
CVE-2026-104988
was published
Oct 2, 2026
User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate...
High
Unreviewed
CVE-2026-104733
was published
Oct 2, 2026
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox...
High
Unreviewed
CVE-2026-104445
was published
Oct 2, 2026
Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.
Moderate
Unreviewed
CVE-2026-103347
was published
Oct 1, 2026
OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing...
Moderate
Unreviewed
CVE-2026-103397
was published
Sep 30, 2026
ProTip!
Advisories are also available from the
GraphQL API