GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
767 advisories
Filter by severity
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc...
High
Unreviewed
CVE-2026-63757
was published
Jul 20, 2026
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows...
High
Unreviewed
CVE-2026-63101
was published
Jul 17, 2026
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video...
High
Unreviewed
CVE-2026-12691
was published
Jul 17, 2026
EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46...
High
Unreviewed
CVE-2024-34268
was published
Jul 16, 2026
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
High
CVE-2026-53714
was published
for
github.com/envoyproxy/gateway
(Go)
Jul 16, 2026
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default
High
CVE-2026-54504
was published
for
@andrea9293/mcp-documentation-server
(npm)
Jul 15, 2026
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information...
High
Unreviewed
CVE-2026-58658
was published
Jul 15, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator...
High
Unreviewed
CVE-2026-24229
was published
Jul 14, 2026
Adobe Experience Manager is affected by a Missing Authentication for Critical Function...
High
Unreviewed
CVE-2026-48252
was published
Jul 14, 2026
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
High
CVE-2026-54446
was published
for
netlicensing-mcp
(pip)
Jul 14, 2026
Missing authentication for critical function in Windows Server Update Service allows an...
High
Unreviewed
CVE-2026-50444
was published
Jul 14, 2026
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS)...
High
Unreviewed
CVE-2026-50451
was published
Jul 14, 2026
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to...
High
Unreviewed
CVE-2026-57969
was published
Jul 14, 2026
Missing authentication for critical function in Windows Spaceport.sys allows an authorized...
High
Unreviewed
CVE-2026-50333
was published
Jul 14, 2026
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
High
GHSA-h4g2-xfmw-q2c9
was published
for
clauster
(pip)
Jul 10, 2026
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication....
High
Unreviewed
CVE-2026-38059
was published
Jul 10, 2026
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling...
High
Unreviewed
CVE-2026-40006
was published
Jul 10, 2026
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication...
High
Unreviewed
CVE-2026-59804
was published
Jul 8, 2026
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
High
CVE-2026-49471
was published
for
serena-agent
(pip)
Jul 8, 2026
An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2026-51937
was published
Jul 8, 2026
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
High
CVE-2026-55786
was published
for
flyto-core
(pip)
Jul 6, 2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
High
Unreviewed
CVE-2026-13125
was published
Jul 2, 2026
Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion...
High
Unreviewed
CVE-2026-56286
was published
Jul 1, 2026
JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication:...
High
Unreviewed
CVE-2026-58375
was published
Jun 30, 2026
Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
High
CVE-2026-49357
was published
for
line-desktop-mcp
(npm)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API