Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

158 advisories

Loading
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison Low
GHSA-8fxq-53rx-ph5f was published for github.com/coder/coder/v2 (Go) Aug 20, 2026
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an... Moderate Unreviewed
CVE-2026-72588 was published Aug 10, 2026
Ghost: Member existence leak via magic link sign-in response Moderate
CVE-2026-53947 was published for ghost (npm) Aug 4, 2026
lukegranto23 Credited to lukegranto23
Budibase: Account Enumeration via Login Lockout Response Differential Moderate
CVE-2026-73306 was published for @budibase/server (npm) Jul 24, 2026
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system Moderate
GHSA-j7f5-gfqm-pcx3 was published for pterodactyl/panel (Composer) Jun 26, 2026
CybranceeHosting Credited to CybranceeHosting, YoloFTW, and TheCyberDesk YoloFTW YoloFTW
TheCyberDesk TheCyberDesk
Vantage6: Set admin user and password from environment or configuration Moderate
CVE-2026-54445 was published for vantage6 (pip) Jun 5, 2026
SnailSploit Credited to SnailSploit
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users Moderate
GHSA-qxrw-f6fh-34r7 was published for lemmy_api (Rust) May 6, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
ProTip! Advisories are also available from the GraphQL API