GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
4,490 advisories
Filter by severity
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
High
CVE-2026-50559
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Jul 29, 2026
An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated
attacker to take...
Moderate
Unreviewed
CVE-2026-63238
was published
Jul 29, 2026
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication...
High
Unreviewed
CVE-2026-13690
was published
Jul 29, 2026
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Moderate
CVE-2026-49447
was published
for
github.com/azukaar/cosmos-server
(Go)
Jul 28, 2026
pytonapi has a Webhook Custom Path Authentication Bypass
High
CVE-2026-54635
was published
for
pytonapi
(pip)
Jul 28, 2026
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Moderate
GHSA-hp74-gm6m-2qm5
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
This issue was addressed with additional restrictions on the lock screen. This issue is fixed in...
Low
Unreviewed
CVE-2026-64745
was published
Jul 27, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-43766
was published
Jul 27, 2026
JFrog Artifactory contains an authentication handling weakness in internal request processing...
High
Unreviewed
CVE-2026-66014
was published
Jul 27, 2026
The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership ...
Moderate
Unreviewed
CVE-2026-14568
was published
Jul 27, 2026
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke...
High
Unreviewed
CVE-2026-9830
was published
Jul 27, 2026
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an...
Critical
Unreviewed
CVE-2026-13332
was published
Jul 27, 2026
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as...
Critical
Unreviewed
CVE-2026-13597
was published
Jul 27, 2026
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not...
High
Unreviewed
CVE-2026-12493
was published
Jul 27, 2026
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its...
High
Unreviewed
CVE-2026-12255
was published
Jul 27, 2026
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
High
GHSA-cmwh-g2h8-c222
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
GHSA-hp6v-6jw7-gv2f
was published
for
@budibase/server
(npm)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Critical
GHSA-r277-6w6q-xmqw
was published
for
github.com/getkin/kin-openapi
(Go)
Jul 24, 2026
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L...
High
Unreviewed
CVE-2026-12504
was published
Jul 24, 2026
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not...
Critical
Unreviewed
CVE-2026-12877
was published
Jul 24, 2026
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2026-62825
was published
Jul 24, 2026
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform...
Critical
Unreviewed
CVE-2026-56191
was published
Jul 24, 2026
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit...
High
Unreviewed
CVE-2026-10697
was published
Jul 23, 2026
ProTip!
Advisories are also available from the
GraphQL API