GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
389 advisories
Filter by severity
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection,...
Moderate
Unreviewed
CVE-2023-45190
was published
Feb 9, 2024
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email...
High
Unreviewed
CVE-2025-31676
was published
Apr 1, 2025
A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic....
Moderate
Unreviewed
CVE-2025-5864
was published
Jun 9, 2025
The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker...
Moderate
Unreviewed
CVE-2025-49195
was published
Jun 12, 2025
vantage6 lacks brute-force protection on change password functionality
Low
CVE-2025-43863
was published
for
vantage6
(pip)
Jun 12, 2025
The product does not implement sufficient measures to prevent multiple failed authentication...
Moderate
Unreviewed
CVE-2025-49186
was published
Jun 12, 2025
Weblate lacks rate limiting when verifying second factor
Moderate
CVE-2025-47951
was published
for
weblate
(pip)
Jun 16, 2025
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting...
High
Unreviewed
CVE-2025-2171
was published
Jun 23, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim...
Critical
Unreviewed
CVE-2025-4383
was published
Jun 26, 2025
Yealink YMCS RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force...
Low
Unreviewed
CVE-2025-52916
was published
Jun 22, 2025
The maxView Storage Manager does not implement sufficient measures to prevent multiple failed...
High
Unreviewed
CVE-2025-1710
was published
Jul 3, 2025
The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed...
High
Unreviewed
CVE-2025-27449
was published
Jul 3, 2025
The SMB server's login mechanism does not implement sufficient measures to prevent multiple...
High
Unreviewed
CVE-2025-27456
was published
Jul 3, 2025
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version...
High
Unreviewed
CVE-2024-23106
was published
Jan 14, 2025
Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
Moderate
CVE-2024-9342
was published
for
org.glassfish.main.admingui:console-common
(Maven)
Jul 16, 2025
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as...
Low
Unreviewed
CVE-2025-7882
was published
Jul 20, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login...
Critical
Unreviewed
CVE-2025-7393
was published
Jul 21, 2025
IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could...
High
Unreviewed
CVE-2024-49342
was published
Jul 28, 2025
Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of...
Moderate
Unreviewed
CVE-2025-28172
was published
Jul 29, 2025
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account...
Moderate
Unreviewed
CVE-2025-54833
was published
Jul 31, 2025
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server...
Low
Unreviewed
CVE-2023-32251
was published
Jul 31, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Moderate
CVE-2025-6004
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Moderate
CVE-2025-6015
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
File Browser vulnerable to insecure password handling
Moderate
CVE-2025-52997
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
ProTip!
Advisories are also available from the
GraphQL API