GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
81 advisories
Filter by severity
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows...
Critical
Unreviewed
CVE-2026-12692
was published
Jul 17, 2026
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change...
High
Unreviewed
CVE-2026-56305
was published
Jul 10, 2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions <...
High
Unreviewed
CVE-2026-54801
was published
Jul 9, 2026
OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
High
CVE-2026-46623
was published
for
org.openidentityplatform.openam:openam-auth-oauth2
(Maven)
Jun 26, 2026
Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user...
High
Unreviewed
CVE-2025-71328
was published
Jun 26, 2026
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change...
High
Unreviewed
CVE-2025-71337
was published
Jun 23, 2026
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password...
Critical
Unreviewed
CVE-2026-5386
was published
May 29, 2026
Unverified password change in Devolutions Server allows an attacker to change a user's password...
Low
Unreviewed
CVE-2026-9249
was published
May 26, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
High
CVE-2026-42084
was published
for
openc3
(RubyGems)
Apr 22, 2026
Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers...
Moderate
Unreviewed
CVE-2019-25653
was published
Mar 30, 2026
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset...
Critical
Unreviewed
CVE-2026-30458
was published
Mar 26, 2026
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication...
High
Unreviewed
CVE-2026-27757
was published
Feb 27, 2026
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the...
High
Unreviewed
CVE-2026-24443
was published
Feb 24, 2026
A vulnerability was identified in vichan-devel vichan up to 5.1.5. This vulnerability affects...
Moderate
Unreviewed
CVE-2026-2543
was published
Feb 16, 2026
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account...
High
Unreviewed
CVE-2026-24440
was published
Jan 26, 2026
A low-privileged user can bypass account credentials without confirming the user's current...
High
Unreviewed
CVE-2025-14751
was published
Jan 23, 2026
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules...
Low
Unreviewed
CVE-2025-11235
was published
Jan 7, 2026
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the...
High
Unreviewed
CVE-2025-13148
was published
Dec 11, 2025
Ibexa User Bundle is missing password change validation
Critical
CVE-2025-67719
was published
for
ibexa/user
(Composer)
Dec 10, 2025
An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7...
Moderate
Unreviewed
CVE-2025-59808
was published
Dec 9, 2025
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2...
Critical
Unreviewed
CVE-2025-63362
was published
Dec 4, 2025
Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change
High
GHSA-fjh6-8679-9pch
was published
for
flowise-ui
(npm)
Nov 14, 2025
Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)
High
GHSA-x39m-3393-3qp4
was published
for
flowise-ui
(npm)
Nov 14, 2025
A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14...
High
Unreviewed
CVE-2025-61132
was published
Oct 23, 2025
ProTip!
Advisories are also available from the
GraphQL API