GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
556 advisories
Filter by severity
phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step...
Critical
Unreviewed
CVE-2026-76213
was published
Aug 19, 2026
Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability...
Moderate
Unreviewed
CVE-2026-73529
was published
Aug 18, 2026
A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the...
Low
Unreviewed
CVE-2026-75773
was published
Aug 18, 2026
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish...
High
Unreviewed
CVE-2026-74868
was published
Aug 17, 2026
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication...
Critical
Unreviewed
CVE-2026-73056
was published
Aug 16, 2026
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts...
High
Unreviewed
CVE-2026-73045
was published
Aug 16, 2026
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth()...
Critical
Unreviewed
CVE-2026-73046
was published
Aug 16, 2026
A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function...
Low
Unreviewed
CVE-2026-19897
was published
Aug 15, 2026
A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function...
Low
Unreviewed
CVE-2026-19898
was published
Aug 15, 2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects...
Low
Unreviewed
CVE-2026-19895
was published
Aug 15, 2026
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access...
Critical
Unreviewed
CVE-2026-19297
was published
Aug 13, 2026
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation...
Moderate
Unreviewed
CVE-2025-62314
was published
Aug 13, 2026
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP...
Moderate
Unreviewed
CVE-2026-66340
was published
Aug 12, 2026
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.
Note: UnixAuth is NOT...
High
Unreviewed
CVE-2026-65948
was published
Aug 10, 2026
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second...
High
Unreviewed
CVE-2026-16619
was published
Aug 7, 2026
Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting,...
Critical
Unreviewed
CVE-2026-71213
was published
Aug 5, 2026
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC...
Moderate
Unreviewed
CVE-2026-71205
was published
Aug 5, 2026
PaperCut NG/MF does not properly restrict excessive authentication attempts within its login...
Moderate
Unreviewed
CVE-2026-8793
was published
Aug 3, 2026
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective...
High
Unreviewed
CVE-2026-16347
was published
Jul 28, 2026
Successful exploitation of this vulnerability
could allow an attacker with local network access...
Low
Unreviewed
CVE-2026-55977
was published
Jul 28, 2026
This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP...
High
Unreviewed
CVE-2026-65894
was published
Jul 27, 2026
Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc...
Moderate
Unreviewed
CVE-2026-8285
was published
Jul 21, 2026
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass...
Moderate
Unreviewed
CVE-2026-62220
was published
Jul 17, 2026
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout...
High
Unreviewed
CVE-2026-14254
was published
Jul 16, 2026
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access...
High
Unreviewed
CVE-2026-61458
was published
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API