GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
149 advisories
Filter by severity
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
Moderate
CVE-2026-54768
was published
for
wp-graphql/wp-graphql
(Composer)
Jul 31, 2026
Budibase: Account Enumeration via Login Lockout Response Differential
Moderate
GHSA-cr7p-cr3q-h5cm
was published
for
@budibase/server
(npm)
Jul 24, 2026
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use...
Moderate
Unreviewed
CVE-2024-23574
was published
Jul 17, 2026
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross...
Moderate
Unreviewed
CVE-2026-47083
was published
Jul 16, 2026
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session...
Critical
Unreviewed
CVE-2026-15747
was published
Jul 14, 2026
SAP HANA Database (user self service tools) allows an unauthenticated user to send specially...
Low
Unreviewed
CVE-2026-44753
was published
Jul 14, 2026
Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint...
Moderate
Unreviewed
CVE-2026-61503
was published
Jul 13, 2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Low
GHSA-gq4g-fpc9-vjfq
was published
for
web-auth/webauthn-lib
(Composer)
Jul 7, 2026
MCO is vulnerable to User Enumeration through authentication-related functionalities. The...
Moderate
Unreviewed
CVE-2026-53908
was published
Jul 1, 2026
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system
Moderate
GHSA-j7f5-gfqm-pcx3
was published
for
pterodactyl/panel
(Composer)
Jun 26, 2026
Vantage6: Set admin user and password from environment or configuration
Moderate
CVE-2026-54445
was published
for
vantage6
(pip)
Jun 5, 2026
Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows...
Critical
Unreviewed
CVE-2026-6207
was published
Jun 5, 2026
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2018-25350
was published
May 26, 2026
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`
Moderate
CVE-2026-45620
was published
for
WWBN/AVideo
(Composer)
May 18, 2026
The check user account lock states feature within the email OTP flow fails to validate user input...
Moderate
Unreviewed
CVE-2024-0391
was published
May 11, 2026
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
Moderate
GHSA-qxrw-f6fh-34r7
was published
for
lemmy_api
(Rust)
May 6, 2026
Statamic CMS vulnerable to email enumeration via forgot password endpoint
Moderate
CVE-2026-44306
was published
for
statamic/cms
(Composer)
May 6, 2026
A vulnerability in an identity management API endpoint of Cisco ISE could allow an...
Moderate
Unreviewed
CVE-2026-20195
was published
May 6, 2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). ...
Moderate
Unreviewed
CVE-2026-34319
was published
Apr 21, 2026
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns...
Moderate
Unreviewed
CVE-2026-34264
was published
Apr 14, 2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances...
High
Unreviewed
CVE-2026-4113
was published
Apr 9, 2026
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid...
Low
Unreviewed
CVE-2025-67806
was published
Apr 1, 2026
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid...
Moderate
Unreviewed
CVE-2025-67807
was published
Apr 1, 2026
User enumeration in ESET Protect (on-prem) via Response Timing.
Moderate
Unreviewed
CVE-2025-3716
was published
Mar 30, 2026
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
Moderate
CVE-2026-33688
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API