GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,086
Maven
5,000+
npm
3,747
NuGet
674
pip
3,436
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
48 advisories
Filter by severity
Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to...
Critical
Unreviewed
CVE-2022-2651
was published
Aug 5, 2022
A vulnerability has been identified in SIMATIC HMI United Comfort Panels (All versions). Affected...
High
Unreviewed
CVE-2020-15787
was published
May 24, 2022
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass...
Moderate
Unreviewed
CVE-2022-3100
was published
Jan 18, 2023
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router...
Critical
Unreviewed
CVE-2023-1833
was published
Apr 14, 2023
Authentication Bypass by Primary Weakness in GitHub repository kareadita/kavita prior to 0.6.0.3.
Critical
Unreviewed
CVE-2022-3993
was published
Nov 14, 2022
A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets...
Critical
Unreviewed
CVE-2021-45031
was published
Mar 31, 2022
A flaw was found in Samba, all versions starting samba 4.5.0 until samba 4.9.15, samba 4.10.10,...
Moderate
Unreviewed
CVE-2019-14833
was published
May 24, 2022
Authentication Bypass by Primary Weakness in GitHub repository mintplex-labs/anything-llm prior...
High
Unreviewed
CVE-2023-4898
was published
Sep 12, 2023
In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all...
Critical
Unreviewed
CVE-2024-1403
was published
Feb 27, 2024
Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security...
Critical
Unreviewed
CVE-2023-7103
was published
Mar 5, 2024
Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication...
Critical
Unreviewed
CVE-2024-1202
was published
Mar 21, 2024
Authentication Bypass by Primary Weakness vulnerability in TeoSOFT Software TeoBASE allows...
Critical
Unreviewed
CVE-2023-6153
was published
Mar 27, 2024
The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID...
Moderate
Unreviewed
CVE-2022-40723
was published
Apr 25, 2023
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could...
Moderate
Unreviewed
CVE-2023-28126
was published
May 10, 2023
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks,...
Critical
Unreviewed
CVE-2023-34124
was published
Jul 13, 2023
SonicWall GMS and Analytics CAS Web Services application use static values for authentication...
Critical
Unreviewed
CVE-2023-34137
was published
Jul 13, 2023
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS...
High
Unreviewed
CVE-2023-2959
was published
Jul 17, 2023
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an...
Critical
Unreviewed
CVE-2023-1935
was published
Aug 3, 2023
Tenda N300 Wireless N VDSL2 Modem Router allows unauthenticated access to pages that in turn...
Moderate
Unreviewed
CVE-2023-4498
was published
Sep 6, 2023
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and...
Moderate
Unreviewed
CVE-2023-4939
was published
Oct 21, 2023
An authentication bypass vulnerability exists in libcurl v8.0.0 where it reuses a previously...
Moderate
Unreviewed
CVE-2023-27538
was published
Mar 30, 2023
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature...
Critical
Unreviewed
CVE-2023-27536
was published
Mar 30, 2023
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse...
High
Unreviewed
CVE-2023-27535
was published
Mar 30, 2023
A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an...
High
Unreviewed
CVE-2024-20378
was published
May 1, 2024
ProTip!
Advisories are also available from the
GraphQL API