GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Critical
CVE-2026-39987
was published
for
marimo
(pip)
Apr 8, 2026
mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
Critical
CVE-2026-0545
was published
for
mlflow
(pip)
Apr 3, 2026
PraisonAI Has Missing Authentication in WebSocket Gateway
Critical
CVE-2026-34952
was published
for
praisonai
(pip)
Apr 1, 2026
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
Critical
CVE-2026-33032
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
MCP Connect has unauthenticated remote OS command execution via /bridge endpoint
Critical
GHSA-wvr4-3wq4-gpc5
was published
for
mcp-bridge
(npm)
Mar 19, 2026
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
Critical
CVE-2026-33017
was published
for
langflow
(pip)
Mar 17, 2026
Linkdave Missing Authentication on REST and WebSocket endpoints
Critical
GHSA-xv8g-fj9h-6gmv
was published
for
github.com/shi-gg/linkdave
(Go)
Mar 10, 2026
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure
Critical
CVE-2026-27944
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 5, 2026
Apache Artemis and Apache ActiveMQ Artemis are Missing Authentication for Critical Functions
Critical
CVE-2026-27446
was published
for
org.apache.activemq:artemis-server
(Maven)
Mar 4, 2026
OpenSTAManager affected by unauthenticated privilege escalation via modules/utenti/actions.php
Critical
CVE-2026-27012
was published
for
devcode-it/openstamanager
(Composer)
Mar 3, 2026
Parse Dashboard has incomplete authentication on AI Agent endpoint
Critical
CVE-2026-27595
was published
for
parse-dashboard
(npm)
Feb 25, 2026
ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
Critical
CVE-2026-27584
was published
for
@actual-app/sync-server
(npm)
Feb 24, 2026
Dagu affected by unauthenticated RCE via inline DAG spec in default configuration
Critical
GHSA-6qr9-g2xw-cw92
was published
for
github.com/dagu-org/dagu
(Go)
Feb 19, 2026
OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated
Critical
CVE-2026-28472
was published
for
openclaw
(npm)
Feb 17, 2026
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
Critical
CVE-2026-26190
was published
for
github.com/milvus-io/milvus
(Go)
Feb 11, 2026
FUXA Unauthenticated Remote Code Execution in Node-RED Integration
Critical
CVE-2026-25938
was published
for
fuxa-server
(npm)
Feb 10, 2026
Keylime Missing Authentication for Critical Function and Improper Authentication
Critical
CVE-2026-1709
was published
for
keylime
(pip)
Feb 6, 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
Critical
CVE-2026-25895
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Critical
CVE-2026-25751
was published
for
fuxa-server
(npm)
Feb 5, 2026
Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
Critical
CVE-2026-25505
was published
for
bambuddy
(pip)
Feb 2, 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
Critical
CVE-2026-23744
was published
for
@mcpjam/inspector
(npm)
Jan 16, 2026
OpenFlagr contains an authentication bypass vulnerability in the HTTP middleware
Critical
CVE-2026-0650
was published
for
github.com/openflagr/flagr
(Go)
Jan 7, 2026
Ollama Platform has missing authentication enabling attackers to perform model management operations
Critical
CVE-2025-63389
was published
for
github.com/ollama/ollama
(Go)
Dec 18, 2025
Step CA Has Authorization Bypass in ACME and SCEP Provisioners
Critical
CVE-2025-44005
was published
for
github.com/smallstep/certificates
(Go)
Dec 3, 2025
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Critical
CVE-2025-58434
was published
for
flowise
(npm)
Sep 12, 2025
ProTip!
Advisories are also available from the
GraphQL API