GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
802 advisories
Filter by severity
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The...
Critical
Unreviewed
CVE-2026-16242
was published
Jul 20, 2026
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access...
Critical
Unreviewed
CVE-2026-9103
was published
Jul 17, 2026
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user...
Critical
Unreviewed
CVE-2026-9202
was published
Jul 17, 2026
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet...
Critical
Unreviewed
CVE-2026-62241
was published
Jul 17, 2026
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows...
Critical
Unreviewed
CVE-2026-63087
was published
Jul 16, 2026
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could...
Critical
Unreviewed
CVE-2026-48325
was published
Jul 14, 2026
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper...
Critical
Unreviewed
CVE-2026-58319
was published
Jul 14, 2026
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a...
Critical
Unreviewed
CVE-2026-10577
was published
Jul 14, 2026
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3...
Critical
Unreviewed
CVE-2026-62422
was published
Jul 14, 2026
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability...
Critical
Unreviewed
CVE-2026-62327
was published
Jul 14, 2026
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows...
Critical
Unreviewed
CVE-2026-59801
was published
Jul 14, 2026
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a...
Critical
Unreviewed
CVE-2026-6847
was published
Jul 13, 2026
The webserver running on port 8090 does not require authentication. This allows for sensitive...
Critical
Unreviewed
CVE-2026-22096
was published
Jul 13, 2026
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
Critical
CVE-2026-54088
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that...
Critical
Unreviewed
CVE-2026-58123
was published
Jul 10, 2026
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
Critical
CVE-2026-53649
was published
for
github.com/BishopFox/joro
(Go)
Jul 8, 2026
mem0's openmemory/api component contains an unauthenticated access vulnerability that allows...
Critical
Unreviewed
CVE-2026-59705
was published
Jul 8, 2026
mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and...
Critical
Unreviewed
CVE-2026-59706
was published
Jul 8, 2026
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2026-58473
was published
Jul 7, 2026
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
Critical
GHSA-vjc7-jrh9-9j86
was published
for
9router
(npm)
Jul 6, 2026
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
Critical
CVE-2026-26190
was published
for
github.com/milvus-io/milvus
(Go)
Feb 11, 2026
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to...
Critical
Unreviewed
CVE-2022-24562
was published
Jun 17, 2022
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP...
Critical
Unreviewed
CVE-2026-4767
was published
Jul 2, 2026
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete
Critical
CVE-2026-50027
was published
for
mcp-memory-service
(pip)
Jul 2, 2026
PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that...
Critical
Unreviewed
CVE-2026-58126
was published
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API