GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
317 advisories
Filter by severity
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48011
was published
May 21, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48010
was published
May 21, 2025
The TYPO3 CMS Backend has Broken Authentication in Backend MFA
High
CVE-2025-47941
was published
for
typo3/cms-backend
(Composer)
May 20, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo -...
Moderate
Unreviewed
CVE-2024-33939
was published
May 19, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA -...
High
Unreviewed
CVE-2025-47710
was published
May 14, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA -...
High
Unreviewed
CVE-2025-47707
was published
May 14, 2025
It was possible to craft an email that showed a tracking link as an attachment. If the user...
High
Unreviewed
CVE-2025-3932
was published
May 14, 2025
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and...
Moderate
Unreviewed
CVE-2025-4427
was published
May 13, 2025
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024...
Critical
Unreviewed
CVE-2025-22462
was published
May 13, 2025
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with...
High
Unreviewed
CVE-2025-40581
was published
May 13, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to...
Moderate
Unreviewed
CVE-2025-0549
was published
May 9, 2025
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication...
Critical
Unreviewed
CVE-2025-3844
was published
May 7, 2025
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus...
Critical
Unreviewed
CVE-2024-12225
was published
May 6, 2025
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-1909
was published
May 5, 2025
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication...
Critical
Unreviewed
CVE-2025-45607
was published
May 5, 2025
Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through...
High
Unreviewed
CVE-2025-47244
was published
May 4, 2025
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Moderate
GHSA-wfm2-rq5g-f8v5
was published
for
@account-kit/smart-contracts
(npm)
Apr 29, 2025
An authentication issue was addressed with improved state management. This issue is fixed in...
High
Unreviewed
CVE-2025-24206
was published
Apr 29, 2025
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be...
Critical
Unreviewed
CVE-2025-2492
was published
Apr 18, 2025
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated...
Low
Unreviewed
CVE-2024-42178
was published
Apr 18, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos allows...
High
Unreviewed
CVE-2025-39535
was published
Apr 17, 2025
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to...
Moderate
Unreviewed
CVE-2025-32357
was published
Apr 5, 2025
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2024-13553
was published
Apr 1, 2025
Apache Pinot Vulnerable to Authentication Bypass
Critical
CVE-2024-56325
was published
for
org.apache.pinot:pinot-broker
(Maven)
Apr 1, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in ho3einie Material...
Critical
Unreviewed
CVE-2025-31095
was published
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API