GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
664 advisories
Filter by severity
In JetBrains YouTrack before 2025.3.161254,
2026.1.14042 improper authentication in YouTrack...
Critical
Unreviewed
CVE-2026-86478
was published
Sep 7, 2026
Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in...
Moderate
Unreviewed
CVE-2026-84186
was published
Sep 7, 2026
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header...
High
Unreviewed
CVE-2026-86196
was published
Sep 5, 2026
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing,...
High
Unreviewed
CVE-2026-85432
was published
Sep 4, 2026
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
High
CVE-2026-72809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
Moderate
Unreviewed
CVE-2026-84766
was published
Sep 3, 2026
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
Moderate
Unreviewed
CVE-2026-84849
was published
Sep 3, 2026
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the...
Critical
Unreviewed
CVE-2026-82180
was published
Sep 3, 2026
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Moderate
CVE-2026-73840
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential...
Critical
Unreviewed
CVE-2026-19117
was published
Sep 2, 2026
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled ...
High
Unreviewed
CVE-2026-14199
was published
Sep 2, 2026
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For...
High
Unreviewed
CVE-2026-84476
was published
Sep 2, 2026
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend...
Critical
Unreviewed
CVE-2026-84479
was published
Sep 2, 2026
A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated...
Moderate
Unreviewed
CVE-2026-73742
was published
Sep 1, 2026
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol...
High
Unreviewed
CVE-2026-19538
was published
Sep 1, 2026
Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated...
High
Unreviewed
CVE-2026-58575
was published
Sep 1, 2026
Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
High
Unreviewed
CVE-2026-82228
was published
Aug 31, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
High
CVE-2026-55641
was published
for
9router
(npm)
Aug 28, 2026
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers
High
CVE-2026-55584
was published
for
phpsysinfo/phpsysinfo
(Composer)
Aug 28, 2026
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor...
Moderate
Unreviewed
CVE-2026-81777
was published
Aug 28, 2026
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address...
Moderate
Unreviewed
CVE-2026-47845
was published
Aug 27, 2026
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
Critical
CVE-2026-49757
was published
for
ash_authentication
(Erlang)
Aug 25, 2026
Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an...
High
Unreviewed
CVE-2026-75037
was published
Aug 25, 2026
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may...
Critical
Unreviewed
CVE-2026-76835
was published
Aug 24, 2026
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in...
High
Unreviewed
CVE-2026-76356
was published
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API