GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
125 advisories
Filter by severity
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized...
Critical
Unreviewed
CVE-2026-62834
was published
Aug 21, 2026
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1...
Critical
Unreviewed
CVE-2021-43716
was published
Aug 18, 2026
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py...
Critical
Unreviewed
CVE-2026-74901
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that...
Critical
Unreviewed
CVE-2026-74876
was published
Aug 17, 2026
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Critical
Unreviewed
CVE-2026-28148
was published
Aug 13, 2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption...
Critical
Unreviewed
CVE-2025-59324
was published
Aug 12, 2026
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept...
Critical
Unreviewed
CVE-2026-10579
was published
Aug 11, 2026
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an...
Critical
Unreviewed
CVE-2026-62873
was published
Aug 7, 2026
The JWT authentication mechanism accepts tokens signed with algorithms other than those...
Critical
Unreviewed
CVE-2026-5430
was published
Aug 6, 2026
An improper verification of cryptographic signature vulnerability in the SAML authentication...
Critical
Unreviewed
CVE-2026-7557
was published
Aug 5, 2026
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
...
Critical
Unreviewed
CVE-2026-9487
was published
Aug 3, 2026
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because...
Critical
Unreviewed
CVE-2026-18108
was published
Aug 3, 2026
The firmware update process for the basemodule of the charging controller only validates the...
Critical
Unreviewed
CVE-2026-44104
was published
Jul 30, 2026
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the...
Critical
Unreviewed
CVE-2026-59243
was published
Jul 29, 2026
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
Critical
CVE-2026-58426
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass...
Critical
Unreviewed
CVE-2026-15013
was published
Jul 16, 2026
A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications...
Critical
Unreviewed
CVE-2026-56451
was published
Jul 14, 2026
The firmware update mechanism does not include cryptographic signature validation. This allows...
Critical
Unreviewed
CVE-2026-22097
was published
Jul 13, 2026
Relyra SAML SignatureValue not cryptographically verified -> authentication bypass
Critical
CVE-2026-49454
was published
for
relyra
(Erlang)
Jun 26, 2026
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
Critical
GHSA-qxvg-h7q2-hcxh
was published
for
motioneye
(pip)
Jun 23, 2026
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
Critical
CVE-2026-54782
was published
for
CoreWCF.Primitives
(NuGet)
Jun 19, 2026
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication...
Critical
Unreviewed
CVE-2026-48558
was published
Jun 12, 2026
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as...
Critical
Unreviewed
CVE-2026-41005
was published
Jun 11, 2026
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8...
Critical
Unreviewed
CVE-2026-36721
was published
Jun 9, 2026
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with...
Critical
Unreviewed
CVE-2026-44748
was published
Jun 9, 2026
ProTip!
Advisories are also available from the
GraphQL API