Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

149 advisories

Loading
lukegranto23 Credited to lukegranto23
Budibase: Account Enumeration via Login Lockout Response Differential Moderate
GHSA-cr7p-cr3q-h5cm was published for @budibase/server (npm) Jul 24, 2026
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system Moderate
GHSA-j7f5-gfqm-pcx3 was published for pterodactyl/panel (Composer) Jun 26, 2026
CybranceeHosting Credited to CybranceeHosting, YoloFTW, and TheCyberDesk YoloFTW YoloFTW
TheCyberDesk TheCyberDesk
Vantage6: Set admin user and password from environment or configuration Moderate
CVE-2026-54445 was published for vantage6 (pip) Jun 5, 2026
SnailSploit Credited to SnailSploit
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users Moderate
GHSA-qxrw-f6fh-34r7 was published for lemmy_api (Rust) May 6, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Statamic CMS vulnerable to email enumeration via forgot password endpoint Moderate
CVE-2026-44306 was published for statamic/cms (Composer) May 6, 2026
emran-alhaddad Credited to emran-alhaddad
A vulnerability in an identity management API endpoint of Cisco ISE could allow an... Moderate Unreviewed
CVE-2026-20195 was published May 6, 2026
User enumeration in ESET Protect (on-prem) via Response Timing. Moderate Unreviewed
CVE-2025-3716 was published Mar 30, 2026
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint Moderate
CVE-2026-33688 was published for wwbn/avideo (Composer) Mar 25, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API