GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
4,895 advisories
Filter by severity
Joomla! Core - [20260914] - Core - MFA Authentication Bypass through rememberme cookies in Joomla...
High
Unreviewed
CVE-2026-92227
was published
Sep 29, 2026
The mechanism binding API-uploaded files to the uploader's authentication method is not working...
Low
Unreviewed
CVE-2026-101269
was published
Sep 29, 2026
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part...
Moderate
Unreviewed
CVE-2026-102248
was published
Sep 29, 2026
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an...
Moderate
Unreviewed
CVE-2026-102245
was published
Sep 29, 2026
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the...
Moderate
Unreviewed
CVE-2026-101280
was published
Sep 29, 2026
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this...
Moderate
Unreviewed
CVE-2026-101281
was published
Sep 29, 2026
mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront...
Moderate
Unreviewed
CVE-2026-102364
was published
Sep 29, 2026
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of...
Critical
Unreviewed
CVE-2026-101077
was published
Sep 28, 2026
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function...
Moderate
Unreviewed
CVE-2026-101073
was published
Sep 28, 2026
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP...
Moderate
Unreviewed
CVE-2026-52749
was published
Sep 28, 2026
A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected...
Moderate
Unreviewed
CVE-2026-101004
was published
Sep 28, 2026
A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part...
Moderate
Unreviewed
CVE-2026-100903
was published
Sep 28, 2026
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4...
Critical
Unreviewed
CVE-2026-100886
was published
Sep 28, 2026
A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to...
Low
Unreviewed
CVE-2026-100876
was published
Sep 27, 2026
Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0...
High
Unreviewed
CVE-2026-101042
was published
Sep 27, 2026
Heym before 0.0.53 fails to verify Slack request signatures when trigger nodes lack credential...
High
Unreviewed
CVE-2026-101049
was published
Sep 27, 2026
Heym before 0.0.53 fails to verify the X-Telegram-Bot-Api-Secret-Token header on Telegram webhook...
High
Unreviewed
CVE-2026-101050
was published
Sep 27, 2026
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall...
High
Unreviewed
CVE-2026-100871
was published
Sep 27, 2026
When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could...
High
Unreviewed
CVE-2026-89136
was published
Sep 27, 2026
Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a...
Low
Unreviewed
CVE-2026-94419
was published
Sep 27, 2026
A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github:...
Moderate
Unreviewed
CVE-2026-100746
was published
Sep 27, 2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable...
Critical
Unreviewed
CVE-2026-85984
was published
Sep 26, 2026
Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens)...
High
Unreviewed
CVE-2026-100709
was published
Sep 26, 2026
Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login...
Critical
Unreviewed
CVE-2026-100684
was published
Sep 26, 2026
Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing...
Critical
Unreviewed
CVE-2026-100607
was published
Sep 26, 2026
ProTip!
Advisories are also available from the
GraphQL API