GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,419 advisories
Filter by severity
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
High
Unreviewed
CVE-2024-35585
was published
Sep 2, 2026
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without...
High
Unreviewed
CVE-2026-84485
was published
Sep 2, 2026
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the...
High
Unreviewed
CVE-2026-84700
was published
Sep 2, 2026
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique...
Critical
Unreviewed
CVE-2026-84696
was published
Sep 2, 2026
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An...
Critical
Unreviewed
CVE-2026-79687
was published
Sep 1, 2026
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd....
High
Unreviewed
CVE-2026-18771
was published
Sep 1, 2026
A security issue exists within ControlFLASH™, where the installer grants write permissions to the...
High
Unreviewed
CVE-2026-12663
was published
Sep 1, 2026
Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure...
High
Unreviewed
CVE-2026-75133
was published
Aug 31, 2026
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote...
Critical
Unreviewed
CVE-2026-66047
was published
Aug 31, 2026
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An...
Critical
Unreviewed
CVE-2026-58574
was published
Aug 31, 2026
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces...
High
Unreviewed
CVE-2026-82641
was published
Aug 30, 2026
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
High
Unreviewed
CVE-2026-82473
was published
Aug 29, 2026
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
High
Unreviewed
CVE-2026-82472
was published
Aug 29, 2026
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where...
Critical
Unreviewed
CVE-2026-82452
was published
Aug 29, 2026
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout...
Critical
Unreviewed
CVE-2026-82277
was published
Aug 28, 2026
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler...
Moderate
Unreviewed
CVE-2026-82276
was published
Aug 28, 2026
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing...
High
Unreviewed
CVE-2026-82282
was published
Aug 28, 2026
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth...
Critical
Unreviewed
CVE-2026-82266
was published
Aug 28, 2026
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without...
Moderate
Unreviewed
CVE-2026-82265
was published
Aug 28, 2026
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Moderate
CVE-2026-55678
was published
for
github.com/basekick-labs/arc
(Go)
Aug 28, 2026
Ebyte gateway product's vendor configuration utility does not require authentication before ...
High
Unreviewed
CVE-2026-77977
was published
Aug 28, 2026
Xiiaozet LK100W exposes a critical management function that can be
invoked without...
Critical
Unreviewed
CVE-2026-78239
was published
Aug 28, 2026
Ebyte device web management interface does not consistently enforce
authentication before...
Critical
Unreviewed
CVE-2026-73125
was published
Aug 28, 2026
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT...
High
Unreviewed
CVE-2026-76640
was published
Aug 27, 2026
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to ...
Critical
Unreviewed
CVE-2026-81735
was published
Aug 27, 2026
ProTip!
Advisories are also available from the
GraphQL API