GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
158 advisories
Filter by severity
Automatisch reveals whether an address is registered through the response to its forgot-password...
Moderate
Unreviewed
CVE-2026-81033
was published
Aug 26, 2026
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an...
Moderate
Unreviewed
CVE-2026-75575
was published
Aug 25, 2026
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose...
High
Unreviewed
CVE-2026-69519
was published
Aug 21, 2026
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Low
GHSA-8fxq-53rx-ph5f
was published
for
github.com/coder/coder/v2
(Go)
Aug 20, 2026
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user...
Moderate
Unreviewed
CVE-2026-14672
was published
Aug 13, 2026
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an...
Moderate
Unreviewed
CVE-2026-72588
was published
Aug 10, 2026
Ghost: Member existence leak via magic link sign-in response
Moderate
CVE-2026-53947
was published
for
ghost
(npm)
Aug 4, 2026
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable...
Critical
Unreviewed
CVE-2026-60007
was published
Aug 4, 2026
Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc....
Moderate
Unreviewed
CVE-2026-14202
was published
Aug 4, 2026
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
Moderate
CVE-2026-54768
was published
for
wp-graphql/wp-graphql
(Composer)
Jul 31, 2026
Budibase: Account Enumeration via Login Lockout Response Differential
Moderate
CVE-2026-73306
was published
for
@budibase/server
(npm)
Jul 24, 2026
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use...
Moderate
Unreviewed
CVE-2024-23574
was published
Jul 17, 2026
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross...
Moderate
Unreviewed
CVE-2026-47083
was published
Jul 16, 2026
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session...
Critical
Unreviewed
CVE-2026-15747
was published
Jul 14, 2026
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially...
Low
Unreviewed
CVE-2026-44753
was published
Jul 14, 2026
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint...
Moderate
Unreviewed
CVE-2026-61503
was published
Jul 13, 2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Low
GHSA-gq4g-fpc9-vjfq
was published
for
web-auth/webauthn-lib
(Composer)
Jul 7, 2026
MCO is vulnerable to User Enumeration through authentication-related functionalities. The...
Moderate
Unreviewed
CVE-2026-53908
was published
Jul 1, 2026
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Moderate
GHSA-j7f5-gfqm-pcx3
was published
for
pterodactyl/panel
(Composer)
Jun 26, 2026
Vantage6: Set admin user and password from environment or configuration
Moderate
CVE-2026-54445
was published
for
vantage6
(pip)
Jun 5, 2026
Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows...
Critical
Unreviewed
CVE-2026-6207
was published
Jun 5, 2026
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2018-25350
was published
May 26, 2026
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`
Moderate
CVE-2026-45620
was published
for
WWBN/AVideo
(Composer)
May 18, 2026
The check user account lock states feature within the email OTP flow fails to validate user input...
Moderate
Unreviewed
CVE-2024-0391
was published
May 11, 2026
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
Moderate
GHSA-qxrw-f6fh-34r7
was published
for
lemmy_api
(Rust)
May 6, 2026
ProTip!
Advisories are also available from the
GraphQL API