GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
139 advisories
Filter by severity
Vantage6: Set admin user and password from environment or configuration
Moderate
GHSA-fgmc-2hqj-86v4
was published
for
vantage6
(pip)
Jun 5, 2026
Observable response discrepancy vulnerability in HAVELSAN Inc. Geographic Tracking System allows...
Critical
Unreviewed
CVE-2026-6207
was published
Jun 5, 2026
userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated...
Critical
Unreviewed
CVE-2018-25350
was published
May 26, 2026
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`
Moderate
CVE-2026-45620
was published
for
WWBN/AVideo
(Composer)
May 18, 2026
The check user account lock states feature within the email OTP flow fails to validate user input...
Moderate
Unreviewed
CVE-2024-0391
was published
May 11, 2026
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
Moderate
GHSA-qxrw-f6fh-34r7
was published
for
lemmy_api
(Rust)
May 6, 2026
Statamic CMS vulnerable to email enumeration via forgot password endpoint
Moderate
CVE-2026-44306
was published
for
statamic/cms
(Composer)
May 6, 2026
A vulnerability in an identity management API endpoint of Cisco ISE could allow an...
Moderate
Unreviewed
CVE-2026-20195
was published
May 6, 2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). ...
Moderate
Unreviewed
CVE-2026-34319
was published
Apr 21, 2026
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns...
Moderate
Unreviewed
CVE-2026-34264
was published
Apr 14, 2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances...
High
Unreviewed
CVE-2026-4113
was published
Apr 9, 2026
The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid...
Low
Unreviewed
CVE-2025-67806
was published
Apr 1, 2026
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid...
Moderate
Unreviewed
CVE-2025-67807
was published
Apr 1, 2026
User enumeration in ESET Protect (on-prem) via Response Timing.
Moderate
Unreviewed
CVE-2025-3716
was published
Mar 30, 2026
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
Moderate
CVE-2026-33688
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
MinIO LDAP login brute-force via user enumeration and missing rate limit
Critical
CVE-2026-33419
was published
for
github.com/minio/minio
(Go)
Mar 20, 2026
Parse Server email verification resend page leaks user existence
Moderate
CVE-2026-33323
was published
for
parse-server
(npm)
Mar 19, 2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an...
Moderate
Unreviewed
CVE-2025-13460
was published
Mar 16, 2026
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in...
Moderate
Unreviewed
CVE-2025-69243
was published
Mar 16, 2026
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43,...
Moderate
Unreviewed
CVE-2026-2859
was published
Mar 13, 2026
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43,...
Moderate
Unreviewed
CVE-2026-24097
was published
Mar 13, 2026
Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing....
Moderate
Unreviewed
CVE-2025-12455
was published
Mar 13, 2026
Shopware has user enumeration via distinct error codes on Store API login endpoint
Moderate
CVE-2026-31888
was published
for
shopware/core
(Composer)
Mar 11, 2026
Parse Server vulnerable to user enumeration via email verification endpoint
Moderate
CVE-2026-31901
was published
for
parse-server
(npm)
Mar 11, 2026
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
Low
CVE-2026-28358
was published
for
nocodb
(npm)
Mar 2, 2026
ProTip!
Advisories are also available from the
GraphQL API