GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
The passwordless login mechanism in CGFIDO from Changing Information Technology has an...
High
Unreviewed
CVE-2024-12838
was published
Dec 31, 2024
Apache HugeGraph-Server: Fixed JWT Token (Secret)
Moderate
CVE-2024-43441
was published
for
org.apache.hugegraph:hugegraph-server
(Maven)
Dec 24, 2024
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services...
Moderate
Unreviewed
CVE-2024-8475
was published
Dec 17, 2024
Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized...
High
Unreviewed
CVE-2024-49056
was published
Nov 12, 2024
This vulnerability exists in LD DP Back Office due to improper implementation of OTP validation...
High
Unreviewed
CVE-2024-47086
was published
Sep 19, 2024
Ant Media Server does not properly authorize non-administrative API calls
Low
CVE-2024-3462
was published
for
io.antmedia:ant-media-server
(Maven)
May 14, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9...
High
Unreviewed
CVE-2024-4024
was published
Apr 25, 2024
The application is vulnerable to an unauthenticated parameter
manipulation that allows an...
High
Unreviewed
CVE-2024-22179
was published
Apr 19, 2024
Electrolink transmitters are vulnerable to an authentication bypass
vulnerability affecting the...
High
Unreviewed
CVE-2024-3741
was published
Apr 19, 2024
TYPO3 vulnerable to Weak Authentication in Session Handling
Moderate
CVE-2023-47127
was published
for
typo3/cms-core
(Composer)
Nov 14, 2023
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest...
Critical
Unreviewed
CVE-2023-4612
was published
Nov 9, 2023
** UNSUPPPORTED WHEN ASSIGNED ** Authentication Bypass by Assumed-Immutable Data vulnerability in...
Critical
Unreviewed
CVE-2023-4669
was published
Sep 14, 2023
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate...
High
Unreviewed
CVE-2022-3875
was published
Dec 19, 2022
TYPO3 CMS vulnerable to Weak Authentication in Frontend Login
Moderate
CVE-2022-23501
was published
for
typo3/cms
(Composer)
Dec 13, 2022
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and...
Moderate
Unreviewed
CVE-2021-1399
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API