GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
77 advisories
Filter by severity
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver...
Critical
Unreviewed
CVE-2026-74880
was published
Aug 17, 2026
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's...
Moderate
Unreviewed
CVE-2026-66832
was published
Aug 11, 2026
Use of GET request method with sensitive query strings vulnerability in Bilin Software and...
High
Unreviewed
CVE-2026-14838
was published
Aug 4, 2026
A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function...
Moderate
Unreviewed
CVE-2026-16207
was published
Jul 19, 2026
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2026-15322
was published
Jul 17, 2026
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to...
High
Unreviewed
CVE-2026-9592
was published
Jul 17, 2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens...
High
Unreviewed
CVE-2026-62386
was published
Jul 17, 2026
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
Moderate
CVE-2026-50157
was published
for
auth0/symfony
(Composer)
Jul 14, 2026
Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and...
High
Unreviewed
CVE-2026-58656
was published
Jul 8, 2026
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
Moderate
GHSA-gj2h-2fpw-fhv9
was published
for
@nuxt/ui
(npm)
Jul 2, 2026
canto-saas-api: OAuth credentials exposed in URL query string and exception messages
Moderate
CVE-2026-55375
was published
for
jleehr/canto-saas-api
(Composer)
Jun 19, 2026
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
Moderate
CVE-2026-47768
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 10, 2026
A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes...
Low
Unreviewed
CVE-2026-10078
was published
May 29, 2026
A use of get request method with sensitive query strings vulnerability in volume encryption of...
Moderate
Unreviewed
CVE-2026-2237
was published
May 27, 2026
HCL AION is affected by a vulnerability where sensitive information may be included in URL...
Low
Unreviewed
CVE-2025-62317
was published
May 14, 2026
Portainer: JWT accepted in URL query leaks tokens to logs and referers
High
CVE-2026-44883
was published
for
github.com/portainer/portainer
(Go)
May 14, 2026
AVideo: Password Hash Leak in MobileManager OAuth Redirect URL Enables Account Takeover
Moderate
CVE-2026-43875
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers...
Moderate
Unreviewed
CVE-2026-37504
was published
May 1, 2026
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
High
CVE-2026-34020
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
Apr 9, 2026
Nhost Leaks Refresh Tokens via URL Query Parameter in OAuth Provider Callback
Low
CVE-2026-34969
was published
for
github.com/nhost/nhost
(Go)
Apr 1, 2026
openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage
Moderate
GHSA-4rh7-jwg9-m28m
was published
for
openssl-encrypt
(pip)
Apr 1, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain...
Low
Unreviewed
CVE-2025-14808
was published
Mar 25, 2026
PinchTab: API Bearer Token Exposed in URL Query Parameter via Server Logs and Intermediary Systems
Moderate
CVE-2026-33620
was published
for
github.com/pinchtab/pinchtab
(Go)
Mar 24, 2026
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state...
Moderate
Unreviewed
CVE-2026-31381
was published
Mar 20, 2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could...
Low
Unreviewed
CVE-2025-14811
was published
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API