GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,049
pip
5,000+
Pub
13
RubyGems
1,128
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
802 advisories
Filter by severity
PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via...
Critical
Unreviewed
CVE-2026-58127
was published
Jul 1, 2026
Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability,...
Critical
Unreviewed
CVE-2026-14162
was published
Jun 30, 2026
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without...
Critical
Unreviewed
CVE-2026-12819
was published
Jun 30, 2026
Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api...
Critical
Unreviewed
CVE-2026-56782
was published
Jun 29, 2026
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
Critical
CVE-2026-49257
was published
for
mcp-pinot-server
(pip)
Jun 26, 2026
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate...
Critical
Unreviewed
CVE-2026-40702
was published
Jun 26, 2026
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account...
Critical
Unreviewed
CVE-2025-71327
was published
Jun 26, 2026
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
Critical
GHSA-qxvg-h7q2-hcxh
was published
for
motioneye
(pip)
Jun 23, 2026
In JetBrains Hub before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,...
Critical
Unreviewed
CVE-2026-50242
was published
Jun 19, 2026
Tilt: Missing authentication on the network-exposed Tilt HUD server
Critical
CVE-2026-55884
was published
for
github.com/tilt-dev/tilt
(Go)
Jun 19, 2026
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
Critical
CVE-2026-48814
was published
for
network-ai
(npm)
Jun 19, 2026
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/...
Critical
Unreviewed
CVE-2026-12046
was published
Jun 19, 2026
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to...
Critical
Unreviewed
CVE-2026-54130
was published
Jun 19, 2026
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and...
Critical
Unreviewed
CVE-2026-54103
was published
Jun 18, 2026
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below...
Critical
Unreviewed
CVE-2026-20253
was published
Jun 10, 2026
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey...
Critical
Unreviewed
CVE-2026-55196
was published
Jun 17, 2026
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component:...
Critical
Unreviewed
CVE-2026-46789
was published
Jun 17, 2026
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Critical
CVE-2026-55450
was published
for
langflow
(pip)
Jun 17, 2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component:...
Critical
Unreviewed
CVE-2026-46879
was published
Jun 17, 2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component:...
Critical
Unreviewed
CVE-2026-46846
was published
Jun 17, 2026
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy...
Critical
Unreviewed
CVE-2026-46807
was published
Jun 17, 2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component:...
Critical
Unreviewed
CVE-2026-46803
was published
Jun 17, 2026
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web...
Critical
Unreviewed
CVE-2026-46905
was published
Jun 17, 2026
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware ...
Critical
Unreviewed
CVE-2026-46781
was published
Jun 17, 2026
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component:...
Critical
Unreviewed
CVE-2026-46799
was published
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API