GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
912
pip
4,768
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,041 advisories
Filter by severity
Oxia has an OIDC token audience validation bypass via SkipClientIDCheck
Critical
GHSA-fhvp-9hcj-6m33
was published
for
github.com/oxia-db/oxia
(Go)
Apr 14, 2026
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
Critical
GHSA-68qg-g8mg-6pr7
was published
for
@paperclipai/server
(npm)
Apr 10, 2026
ajenti.plugin.core has password bypass when 2FA is activated
Critical
CVE-2026-40177
was published
for
ajenti.plugin.core
(pip)
Apr 10, 2026
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
Critical
CVE-2026-29145
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 9, 2026
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
Critical
CVE-2026-39324
was published
for
rack-session
(RubyGems)
Apr 8, 2026
ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication...
Critical
Unreviewed
CVE-2017-20235
was published
Apr 4, 2026
Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE...
Critical
Unreviewed
CVE-2018-25236
was published
Apr 4, 2026
LiteLLM: Authentication bypass via OIDC userinfo cache key collision
Critical
CVE-2026-35030
was published
for
litellm
(pip)
Apr 3, 2026
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication...
Critical
Unreviewed
CVE-2017-20237
was published
Apr 3, 2026
Hirschmann HiEOS devices contain an authentication bypass vulnerability in the HTTP(S) management...
Critical
Unreviewed
CVE-2024-14034
was published
Apr 2, 2026
Juju has Improper TLS Client/Server authentication and certificate verification on Database Cluster
Critical
CVE-2026-4370
was published
for
github.com/juju/juju
(Go)
Apr 2, 2026
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while...
Critical
Unreviewed
CVE-2026-34873
was published
Apr 1, 2026
The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's...
Critical
Unreviewed
CVE-2025-15484
was published
Apr 1, 2026
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user...
Critical
Unreviewed
CVE-2025-71279
was published
Apr 1, 2026
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
Critical
CVE-2026-33716
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
MinIO has JWT Algorithm Confusion in OIDC Authentication
Critical
CVE-2026-33322
was published
for
github.com/minio/minio
(Go)
Mar 19, 2026
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
Critical
CVE-2026-30836
was published
for
github.com/smallstep/certificates
(Go)
Mar 19, 2026
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2026-2991
was published
Mar 18, 2026
AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass
Critical
CVE-2026-32136
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Mar 12, 2026
A vulnerability has been identified in the web-based management interface of AOS-CX switches that...
Critical
Unreviewed
CVE-2026-23813
was published
Mar 11, 2026
Feathers has an OAuth Callback Account Takeover issue
Critical
CVE-2026-29792
was published
for
@feathersjs/authentication-oauth
(npm)
Mar 10, 2026
The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up...
Critical
Unreviewed
CVE-2026-0953
was published
Mar 10, 2026
Parse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adapters
Critical
CVE-2026-30863
was published
for
parse-server
(npm)
Mar 9, 2026
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions...
Critical
Unreviewed
CVE-2026-3224
was published
Mar 4, 2026
A remote authentication bypass vulnerability
exists in HPE AutoPass License Server (APLS).
Critical
Unreviewed
CVE-2026-23600
was published
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API