GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,638
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,425 advisories
Filter by severity
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Critical
CVE-2026-73843
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export...
Moderate
Unreviewed
CVE-2025-15481
was published
Sep 2, 2026
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
Critical
CVE-2026-72920
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Sep 2, 2026
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
High
Unreviewed
CVE-2024-35585
was published
Sep 2, 2026
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without...
High
Unreviewed
CVE-2026-84485
was published
Sep 2, 2026
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the...
High
Unreviewed
CVE-2026-84700
was published
Sep 2, 2026
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique...
Critical
Unreviewed
CVE-2026-84696
was published
Sep 2, 2026
A vulnerability has been identified in the underlying operating system of HPE Networking Fabric...
Moderate
Unreviewed
CVE-2026-73726
was published
Sep 1, 2026
A vulnerability in the API of HPE Networking Fabric Composer could allow an unauthenticated...
High
Unreviewed
CVE-2026-73706
was published
Sep 1, 2026
Vulnerabilities in an API endpoint of HPE Networking Fabric Composer could allow an...
High
Unreviewed
CVE-2026-73710
was published
Sep 1, 2026
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An...
Critical
Unreviewed
CVE-2026-79687
was published
Sep 1, 2026
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd....
High
Unreviewed
CVE-2026-18771
was published
Sep 1, 2026
A security issue exists within ControlFLASH™, where the installer grants write permissions to the...
High
Unreviewed
CVE-2026-12663
was published
Sep 1, 2026
Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure...
High
Unreviewed
CVE-2026-75133
was published
Aug 31, 2026
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote...
Critical
Unreviewed
CVE-2026-66047
was published
Aug 31, 2026
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An...
Critical
Unreviewed
CVE-2026-58574
was published
Aug 31, 2026
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces...
High
Unreviewed
CVE-2026-82641
was published
Aug 30, 2026
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
High
Unreviewed
CVE-2026-82473
was published
Aug 29, 2026
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
High
Unreviewed
CVE-2026-82472
was published
Aug 29, 2026
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where...
Critical
Unreviewed
CVE-2026-82452
was published
Aug 29, 2026
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout...
Critical
Unreviewed
CVE-2026-82277
was published
Aug 28, 2026
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler...
Moderate
Unreviewed
CVE-2026-82276
was published
Aug 28, 2026
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing...
High
Unreviewed
CVE-2026-82282
was published
Aug 28, 2026
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth...
Critical
Unreviewed
CVE-2026-82266
was published
Aug 28, 2026
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without...
Moderate
Unreviewed
CVE-2026-82265
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API