GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
888 advisories
Filter by severity
Magento Broken authentication and session managememt
Critical
CVE-2019-8149
was published
for
magento/community-edition
(Composer)
May 24, 2022
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and...
Critical
Unreviewed
CVE-2024-3263
was published
May 14, 2024
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass...
Critical
Unreviewed
CVE-2023-38096
was published
May 3, 2024
OpenStack Octavia Amphora-Agent not requiring Client-Certificate
Critical
CVE-2019-17134
was published
for
octavia
(pip)
May 24, 2022
Contao Does Not Expire Tokens Correctly
Critical
CVE-2019-10643
was published
for
contao/contao
(Composer)
May 13, 2022
Symfony Authentication Bypass
Critical
CVE-2018-11407
was published
for
symfony/security
(Composer)
May 14, 2022
GeniXCMS Arbitrary User Password Reset Vulnerability
Critical
CVE-2017-8827
was published
for
genix/cms
(Composer)
May 17, 2022
Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows...
Critical
Unreviewed
CVE-2023-51484
was published
Apr 25, 2024
Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing...
Critical
Unreviewed
CVE-2023-51482
was published
Apr 25, 2024
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege...
Critical
Unreviewed
CVE-2023-51478
was published
Apr 25, 2024
ThinkAdmin Administrator cookies still working after password change
Critical
CVE-2019-11018
was published
for
zoujingli/thinkadmin
(Composer)
May 13, 2022
Gitea Allows 1FA Even for 2FA-Enrolled Accounts
Critical
CVE-2019-11576
was published
for
code.gitea.io/gitea
(Go)
May 24, 2022
Dolibarr Improper Restriction of Excessive Authentication Attempts
Critical
CVE-2020-7995
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing...
Critical
Unreviewed
CVE-2023-51477
was published
Apr 24, 2024
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege...
Critical
Unreviewed
CVE-2023-51472
was published
Apr 24, 2024
Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
Critical
CVE-2021-32637
was published
for
github.com/authelia/authelia/v4
(Go)
Dec 20, 2021
Authorization Bypass in Spring Security
Critical
CVE-2014-3527
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 15, 2020
Microsoft Exchange Server Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2024-21410
was published
Feb 13, 2024
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main...
Critical
Unreviewed
CVE-2023-4562
was published
Oct 13, 2023
Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows...
Critical
Unreviewed
CVE-2023-3065
was published
Jun 5, 2023
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even...
Critical
Unreviewed
CVE-2023-3028
was published
Jul 6, 2023
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in...
Critical
Unreviewed
CVE-2013-3072
was published
May 5, 2022
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due...
Critical
Unreviewed
CVE-2023-6483
was published
Dec 22, 2023
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature...
Critical
Unreviewed
CVE-2023-27536
was published
Mar 30, 2023
Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier...
Critical
Unreviewed
CVE-2023-26573
was published
Oct 25, 2023
ProTip!
Advisories are also available from the
GraphQL API