GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
324 advisories
Filter by severity
A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior...
High
Unreviewed
CVE-2026-75946
was published
Aug 21, 2026
node-opcua missing nonce verification in UserNameIdentityToken authentication
High
CVE-2026-54155
was published
for
node-opcua
(npm)
Aug 20, 2026
libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain...
High
Unreviewed
CVE-2026-76234
was published
Aug 19, 2026
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System...
High
Unreviewed
CVE-2025-9210
was published
Aug 18, 2026
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
High
GHSA-fhgh-wq4q-r37x
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
High
Unreviewed
CVE-2026-19910
was published
Aug 14, 2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551...
High
Unreviewed
CVE-2026-12263
was published
Aug 13, 2026
A holder of a valid integration credential may impersonate other users under specific conditions.
High
Unreviewed
CVE-2026-68759
was published
Aug 12, 2026
A user with access to a valid SAML response may impersonate another user under specific conditions.
High
Unreviewed
CVE-2026-68757
was published
Aug 12, 2026
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate...
High
Unreviewed
CVE-2025-59327
was published
Aug 12, 2026
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero...
High
Unreviewed
CVE-2026-15556
was published
Aug 11, 2026
Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of...
High
Unreviewed
CVE-2026-10754
was published
Aug 10, 2026
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized...
High
Unreviewed
CVE-2026-62918
was published
Aug 7, 2026
A flaw was found in the SAML metadata import functionality of the keycloak-services component,...
High
Unreviewed
CVE-2026-16443
was published
Aug 5, 2026
XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because...
High
Unreviewed
CVE-2026-18568
was published
Aug 3, 2026
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature...
High
Unreviewed
CVE-2026-18092
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL...
High
Unreviewed
CVE-2026-12860
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored....
High
Unreviewed
CVE-2026-59643
was published
Aug 3, 2026
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero...
High
Unreviewed
CVE-2026-59639
was published
Aug 3, 2026
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
High
CVE-2026-53501
was published
for
thumbor
(pip)
Jul 31, 2026
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a...
High
Unreviewed
CVE-2026-65616
was published
Jul 27, 2026
Multiple Lenze products are affected by an improper signature verification vulnerability in the...
High
Unreviewed
CVE-2026-14837
was published
Jul 27, 2026
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a...
High
Unreviewed
CVE-2026-13089
was published
Jul 22, 2026
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
High
CVE-2026-47304
was published
for
System.Security.Cryptography.Xml
(NuGet)
Jul 20, 2026
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability...
High
Unreviewed
CVE-2026-64623
was published
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API