GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
689 advisories
Filter by severity
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the...
Unknown
Unreviewed
CVE-2026-59243
was published
Jul 29, 2026
A TOTP two-factor authentication bypass vulnerability in
Koollab LMS allowed an
attacker to...
Moderate
Unreviewed
CVE-2026-63237
was published
Jul 29, 2026
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a...
High
Unreviewed
CVE-2026-65616
was published
Jul 27, 2026
Multiple Lenze products are affected by an improper signature verification vulnerability in the...
High
Unreviewed
CVE-2026-14837
was published
Jul 27, 2026
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are...
Low
Unreviewed
CVE-2026-52686
was published
Jul 23, 2026
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a...
High
Unreviewed
CVE-2026-13089
was published
Jul 22, 2026
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to...
Moderate
Unreviewed
CVE-2026-10723
was published
Jul 22, 2026
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Critical
CVE-2026-58426
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability...
High
Unreviewed
CVE-2026-64623
was published
Jul 20, 2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass...
Critical
Unreviewed
CVE-2026-15013
was published
Jul 16, 2026
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications...
Critical
Unreviewed
CVE-2026-56451
was published
Jul 14, 2026
The firmware update mechanism does not include cryptographic signature validation. This allows...
Critical
Unreviewed
CVE-2026-22097
was published
Jul 13, 2026
YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
High
CVE-2026-52767
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass...
Moderate
Unreviewed
CVE-2026-9027
was published
Jul 9, 2026
Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows...
High
Unreviewed
CVE-2026-11348
was published
Jul 7, 2026
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via...
High
Unreviewed
CVE-2026-13722
was published
Jul 3, 2026
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
High
Unreviewed
CVE-2026-50722
was published
Jul 3, 2026
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
High
Unreviewed
CVE-2026-50721
was published
Jul 3, 2026
CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper...
Low
Unreviewed
CVE-2026-13743
was published
Jul 2, 2026
Centrifugo's dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass
High
CVE-2026-49998
was published
for
github.com/centrifugal/centrifugo
(Go)
Jul 1, 2026
sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
High
CVE-2026-48815
was published
for
sigstore
(npm)
Jul 1, 2026
Sigstore Java has a vulnerability with bundle verification of integratedTime
Low
CVE-2026-48791
was published
for
dev.sigstore:sigstore-java
(Maven)
Jun 30, 2026
Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23,...
Low
Unreviewed
CVE-2025-0824
was published
Jun 29, 2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious...
Moderate
Unreviewed
CVE-2024-23581
was published
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API