GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,494
Maven
5,000+
npm
4,129
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
389 advisories
Filter by severity
HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability...
Low
Unreviewed
CVE-2024-42176
was published
Mar 19, 2025
A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass...
Critical
Unreviewed
CVE-2025-25595
was published
Mar 18, 2025
IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote...
High
Unreviewed
CVE-2024-51476
was published
Mar 6, 2025
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has...
Moderate
Unreviewed
CVE-2025-1629
was published
Feb 24, 2025
Authelia applies regulation separately to Username-based logins to Email-based logins
Low
CVE-2025-24806
was published
for
github.com/authelia/authelia/v4
(Go)
Feb 19, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real...
Moderate
Unreviewed
CVE-2025-22645
was published
Feb 18, 2025
Easy!Appointments Improper Restriction of Excessive Authentication Attempts
Critical
CVE-2024-57602
was published
for
alextselegidis/easyappointments
(Composer)
Feb 13, 2025
Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
Moderate
CVE-2024-57610
was published
for
sylius/sylius
(Composer)
Feb 6, 2025
•
withdrawn
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version...
High
Unreviewed
CVE-2024-23106
was published
Jan 14, 2025
JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where...
High
Unreviewed
CVE-2024-55008
was published
Jan 7, 2025
Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an...
Moderate
Unreviewed
CVE-2024-53647
was published
Dec 31, 2024
Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of...
Moderate
Unreviewed
CVE-2024-38488
was published
Dec 13, 2024
An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication...
Critical
Unreviewed
CVE-2024-46442
was published
Dec 10, 2024
A vulnerability exists in NSD570 login panel that does not restrict excessive authentication...
Moderate
Unreviewed
CVE-2024-9928
was published
Nov 26, 2024
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of...
High
Unreviewed
CVE-2024-49597
was published
Nov 26, 2024
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2024-5716
was published
Nov 22, 2024
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block...
Moderate
Unreviewed
CVE-2024-0787
was published
Nov 15, 2024
There is no limit on the number of failed login attempts permitted with the Clinician Password or...
Critical
Unreviewed
CVE-2024-9832
was published
Nov 14, 2024
An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server...
Moderate
Unreviewed
CVE-2024-51720
was published
Nov 12, 2024
A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic....
Low
Unreviewed
CVE-2024-11126
was published
Nov 12, 2024
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality...
Moderate
Unreviewed
CVE-2024-47592
was published
Nov 12, 2024
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed...
Critical
Unreviewed
CVE-2024-51558
was published
Nov 4, 2024
A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS...
Critical
Unreviewed
CVE-2024-48143
was published
Oct 24, 2024
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential...
High
Unreviewed
CVE-2024-7292
was published
Oct 9, 2024
ProTip!
Advisories are also available from the
GraphQL API