GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
122 advisories
Filter by severity
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can...
Low
Unreviewed
CVE-2026-23922
was published
Aug 18, 2026
A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma®...
Low
Unreviewed
CVE-2026-0289
was published
Aug 13, 2026
An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks...
Low
Unreviewed
CVE-2026-0290
was published
Aug 13, 2026
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Low
GHSA-gx4c-2hqx-cw2r
was published
for
github.com/rclone/rclone
(Go)
Aug 5, 2026
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive...
Low
Unreviewed
CVE-2026-56570
was published
Jul 31, 2026
File Browser: Share API exposes the password hash and bypass token
Low
CVE-2026-62684
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an...
Low
Unreviewed
CVE-2026-9395
was published
May 26, 2026
HCL AION is affected by a vulnerability where basic authorization tokens are used for...
Low
Unreviewed
CVE-2025-62312
was published
May 14, 2026
HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text”...
Low
Unreviewed
CVE-2025-62345
was published
May 6, 2026
A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function...
Low
Unreviewed
CVE-2026-7038
was published
Apr 26, 2026
Tanium addressed an information disclosure vulnerability in Tanium Server.
Low
Unreviewed
CVE-2026-6408
was published
Apr 22, 2026
A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5...
Low
Unreviewed
CVE-2026-27316
was published
Apr 14, 2026
Duplicate Advisory: OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
GHSA-8mr2-f9wf-hcfq
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw reuses the gateway auth token in the owner ID prompt hashing fallback
Low
CVE-2026-32897
was published
for
openclaw
(npm)
Mar 3, 2026
Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
Low
CVE-2026-27167
was published
for
gradio
(pip)
Mar 1, 2026
NeuVector scanner insecurely handles passwords as command arguments
Low
CVE-2025-67860
was published
for
github.com/neuvector/scanner
(Go)
Feb 12, 2026
YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the...
Low
Unreviewed
CVE-2026-1966
was published
Feb 5, 2026
HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field...
Low
Unreviewed
CVE-2025-52623
was published
Feb 3, 2026
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a...
Low
Unreviewed
CVE-2025-9521
was published
Jan 26, 2026
Insufficiently Protected Credentials vulnerability in Broadcom DX NetOps Spectrum on Windows,...
Low
Unreviewed
CVE-2025-69271
was published
Jan 12, 2026
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server:...
Low
Unreviewed
CVE-2025-13758
was published
Nov 27, 2025
Ericsson
Indoor Connect 8855 contains a vulnerability where server-side security can be
bypassed...
Low
Unreviewed
CVE-2025-40838
was published
Sep 25, 2025
Mattermost has Insufficiently Protected Credentials
Low
CVE-2025-6227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
Low
CVE-2025-53661
was published
for
io.jenkins.plugins:testsigma
(Maven)
Jul 9, 2025
A vulnerability, which was classified as problematic, has been found in 70mai M300 up to 20250611...
Low
Unreviewed
CVE-2025-6526
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API