GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,505
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,261 advisories
Filter by severity
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that...
High
Unreviewed
CVE-2026-69111
was published
Aug 5, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Insufficient Verification of Data Authenticity vulnerability in Apache Answer.
This issue...
High
Unreviewed
CVE-2026-48911
was published
Aug 5, 2026
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default...
Critical
Unreviewed
CVE-2026-71289
was published
Aug 5, 2026
IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other...
Critical
Unreviewed
CVE-2026-71262
was published
Aug 5, 2026
Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and ...
High
Unreviewed
CVE-2026-71241
was published
Aug 5, 2026
changedetection.io's REST API resources are protected by an @auth.check_token decorator...
Moderate
Unreviewed
CVE-2026-71203
was published
Aug 5, 2026
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts)...
Critical
Unreviewed
CVE-2026-71214
was published
Aug 5, 2026
MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX...
Critical
Unreviewed
CVE-2026-70552
was published
Aug 4, 2026
Atlas-Livre contains an improper access control vulnerability in the admin controllers under...
Critical
Unreviewed
CVE-2026-69703
was published
Aug 4, 2026
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access...
High
Unreviewed
CVE-2026-58071
was published
Aug 4, 2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could...
Critical
Unreviewed
CVE-2026-63455
was published
Aug 4, 2026
Cryptographic Issue while processing registration requests with malformed or missing...
High
Unreviewed
CVE-2026-24079
was published
Aug 4, 2026
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass...
Critical
Unreviewed
CVE-2026-61514
was published
Aug 4, 2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing...
High
Unreviewed
CVE-2026-59913
was published
Aug 3, 2026
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that...
Critical
Unreviewed
CVE-2026-41452
was published
Aug 3, 2026
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic...
High
Unreviewed
CVE-2026-67610
was published
Aug 3, 2026
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when...
High
Unreviewed
CVE-2026-69091
was published
Aug 3, 2026
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP...
High
Unreviewed
CVE-2026-68578
was published
Aug 2, 2026
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator...
Moderate
Unreviewed
CVE-2026-17348
was published
Jul 31, 2026
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
High
GHSA-p7w7-4929-vpj5
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions,...
High
Unreviewed
CVE-2026-65310
was published
Jul 31, 2026
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug...
High
Unreviewed
CVE-2026-12562
was published
Jul 31, 2026
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2026-67208
was published
Jul 30, 2026
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows...
Critical
Unreviewed
CVE-2026-67594
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API