GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
57
GitHub Actions
50
Go
3,767
Maven
5,000+
npm
5,000+
NuGet
937
pip
4,999
Pub
13
RubyGems
1,058
Rust
1,347
Swift
54
Unreviewed advisories
All unreviewed
5,000+
133 advisories
Filter by severity
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
Moderate
GHSA-qxrw-f6fh-34r7
was published
for
lemmy_api
(Rust)
May 6, 2026
Statamic CMS vulnerable to email enumeration via forgot password endpoint
Moderate
CVE-2026-44306
was published
for
statamic/cms
(Composer)
May 6, 2026
A vulnerability in an identity management API endpoint of Cisco ISE could allow an...
Moderate
Unreviewed
CVE-2026-20195
was published
May 6, 2026
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). ...
Moderate
Unreviewed
CVE-2026-34319
was published
Apr 21, 2026
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns...
Moderate
Unreviewed
CVE-2026-34264
was published
Apr 14, 2026
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances...
High
Unreviewed
CVE-2026-4113
was published
Apr 9, 2026
The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid...
Moderate
Unreviewed
CVE-2025-67807
was published
Apr 1, 2026
User enumeration in ESET Protect (on-prem) via Response Timing.
Moderate
Unreviewed
CVE-2025-3716
was published
Mar 30, 2026
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
Moderate
CVE-2026-33688
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
MinIO LDAP login brute-force via user enumeration and missing rate limit
Critical
CVE-2026-33419
was published
for
github.com/minio/minio
(Go)
Mar 20, 2026
Parse Server email verification resend page leaks user existence
Moderate
CVE-2026-33323
was published
for
parse-server
(npm)
Mar 19, 2026
IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an...
Moderate
Unreviewed
CVE-2025-13460
was published
Mar 16, 2026
Raytha CMS is vulnerable to User Enumeration in password reset functionality. Difference in...
Moderate
Unreviewed
CVE-2025-69243
was published
Mar 16, 2026
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43,...
Moderate
Unreviewed
CVE-2026-24097
was published
Mar 13, 2026
Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43,...
Moderate
Unreviewed
CVE-2026-2859
was published
Mar 13, 2026
Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing....
Moderate
Unreviewed
CVE-2025-12455
was published
Mar 13, 2026
Shopware has user enumeration via distinct error codes on Store API login endpoint
Moderate
CVE-2026-31888
was published
for
shopware/core
(Composer)
Mar 11, 2026
Parse Server vulnerable to user enumeration via email verification endpoint
Moderate
CVE-2026-31901
was published
for
parse-server
(npm)
Mar 11, 2026
NocoDB Vulnerable to User Enumeration via Password Reset Endpoint
Low
CVE-2026-28358
was published
for
nocodb
(npm)
Mar 2, 2026
Rucio WebUI has Username Enumeration via Login Error Message
Moderate
CVE-2026-25138
was published
for
rucio-webui
(pip)
Feb 25, 2026
Static Web Server affected by timing-based username enumeration in Basic Authentication due to early response on invalid usernames
Moderate
CVE-2026-27480
was published
for
static-web-server
(Rust)
Feb 20, 2026
A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery...
Moderate
Unreviewed
CVE-2026-26744
was published
Feb 20, 2026
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset...
Moderate
Unreviewed
CVE-2019-25338
was published
Feb 13, 2026
CI4MS Vulnerable to User Email Enumeration via Password Reset Flow
Moderate
CVE-2026-25509
was published
for
ci4-cms-erp/ci4ms
(Composer)
Feb 2, 2026
Discord through 2026-01-16 allows gathering information about whether a user's client state is...
Moderate
Unreviewed
CVE-2026-24332
was published
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API