GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
611 advisories
Filter by severity
Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header...
High
Unreviewed
CVE-2026-55202
was published
Jun 17, 2026
LiteLLM: Authentication Bypass via Host Header Injection
Critical
CVE-2026-49468
was published
for
litellm
(pip)
Jun 16, 2026
Duplicate Advisory: Zalo allowFrom could bind to mutable display names
High
GHSA-w7m7-3xcf-mp48
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
Duplicate Advisory: Discord allowFrom could bind to mutable display names
High
GHSA-p44v-rx83-vjp4
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
High
CVE-2026-52845
was published
for
github.com/caddyserver/caddy
(Go)
Jun 16, 2026
n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
Moderate
CVE-2026-54308
was published
for
n8n
(npm)
Jun 16, 2026
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
Moderate
Unreviewed
CVE-2026-42662
was published
Jun 15, 2026
Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
High
Unreviewed
CVE-2026-27089
was published
Jun 15, 2026
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization...
Critical
Unreviewed
CVE-2026-36537
was published
Jun 15, 2026
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction...
Moderate
Unreviewed
CVE-2026-34025
was published
Jun 15, 2026
OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming...
High
Unreviewed
CVE-2026-53833
was published
Jun 13, 2026
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local...
High
Unreviewed
CVE-2026-53832
was published
Jun 13, 2026
OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature...
High
Unreviewed
CVE-2026-53823
was published
Jun 13, 2026
Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media...
Moderate
Unreviewed
CVE-2026-5792
was published
Jun 12, 2026
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
Critical
CVE-2026-48063
was published
for
@whiskeysockets/baileys
(npm)
Jun 10, 2026
A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could...
High
Unreviewed
CVE-2026-6090
was published
Jun 10, 2026
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
High
CVE-2026-47737
was published
for
puma
(RubyGems)
Jun 9, 2026
NocoDB: Cross-Workspace Integration Use in Connection Test
Moderate
CVE-2026-47381
was published
for
nocodb
(npm)
Jun 5, 2026
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2026-48567
was published
Jun 5, 2026
Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53...
Moderate
Unreviewed
CVE-2026-11019
was published
Jun 5, 2026
Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote...
Moderate
Unreviewed
CVE-2026-11001
was published
Jun 5, 2026
Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment
Moderate
CVE-2026-48016
was published
for
shopware/core
(Composer)
Jun 4, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Moderate
CVE-2026-45056
was published
for
matrix-sdk-crypto
(Rust)
Jun 4, 2026
Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret
Moderate
CVE-2026-44476
was published
for
doorkeeper-openid_connect
(RubyGems)
Jun 4, 2026
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
Critical
Unreviewed
CVE-2026-8644
was published
Jun 1, 2026
ProTip!
Advisories are also available from the
GraphQL API