GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
2,125 advisories
Filter by severity
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could...
Critical
Unreviewed
CVE-2026-48325
was published
Jul 14, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing...
Moderate
Unreviewed
CVE-2026-24259
was published
Jul 14, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator...
High
Unreviewed
CVE-2026-24229
was published
Jul 14, 2026
Adobe Experience Manager is affected by a Missing Authentication for Critical Function...
High
Unreviewed
CVE-2026-48252
was published
Jul 14, 2026
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
High
CVE-2026-54446
was published
for
netlicensing-mcp
(pip)
Jul 14, 2026
Missing authentication for critical function in Windows Server Update Service allows an...
High
Unreviewed
CVE-2026-50444
was published
Jul 14, 2026
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS)...
High
Unreviewed
CVE-2026-50451
was published
Jul 14, 2026
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to...
High
Unreviewed
CVE-2026-57969
was published
Jul 14, 2026
Missing authentication for critical function in Microsoft Office SharePoint allows an...
Moderate
Unreviewed
CVE-2026-56164
was published
Jul 14, 2026
Missing authentication for critical function in Windows Spaceport.sys allows an authorized...
High
Unreviewed
CVE-2026-50333
was published
Jul 14, 2026
Missing authentication for critical function in Microsoft Windows DNS allows an authorized...
Moderate
Unreviewed
CVE-2026-49174
was published
Jul 14, 2026
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a...
Critical
Unreviewed
CVE-2026-10577
was published
Jul 14, 2026
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3...
Critical
Unreviewed
CVE-2026-62422
was published
Jul 14, 2026
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper...
Critical
Unreviewed
CVE-2026-58319
was published
Jul 14, 2026
setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled...
Moderate
Unreviewed
CVE-2026-44767
was published
Jul 14, 2026
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability...
Critical
Unreviewed
CVE-2026-62327
was published
Jul 14, 2026
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows...
Critical
Unreviewed
CVE-2026-59801
was published
Jul 14, 2026
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a...
Critical
Unreviewed
CVE-2026-6847
was published
Jul 13, 2026
The webserver running on port 8090 does not require authentication. This allows for sensitive...
Critical
Unreviewed
CVE-2026-22096
was published
Jul 13, 2026
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
High
GHSA-h4g2-xfmw-q2c9
was published
for
clauster
(pip)
Jul 10, 2026
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
Critical
CVE-2026-54088
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
Moderate
CVE-2026-54068
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker...
Moderate
Unreviewed
CVE-2026-57476
was published
Jul 10, 2026
Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API...
Moderate
Unreviewed
CVE-2026-57475
was published
Jul 10, 2026
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication....
High
Unreviewed
CVE-2026-38059
was published
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API