GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
188 advisories
Filter by severity
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a...
High
Unreviewed
CVE-2021-31912
was published
May 24, 2022
Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This...
High
Unreviewed
CVE-2021-29080
was published
May 24, 2022
The default setting of MISP 2.4.136 did not enable the requirements (aka...
Critical
Unreviewed
CVE-2021-25323
was published
May 24, 2022
Select Dell Client Commercial and Consumer platforms support a BIOS password reset capability...
High
Unreviewed
CVE-2020-5361
was published
May 24, 2022
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the...
High
Unreviewed
CVE-2020-28186
was published
May 24, 2022
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account...
High
Unreviewed
CVE-2020-15949
was published
May 24, 2022
konzept-ix publiXone before 2020.015 allows attackers to take over arbitrary user accounts by...
Critical
Unreviewed
CVE-2020-27179
was published
May 24, 2022
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an...
High
Unreviewed
CVE-2020-26061
was published
May 24, 2022
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is...
Moderate
Unreviewed
CVE-2020-5899
was published
May 24, 2022
An issue was discovered in Navigate CMS 2.9 r1433. The forgot-password feature allows users to...
Moderate
Unreviewed
CVE-2020-14016
was published
May 24, 2022
Craft CMS possibility of brute force attempts
Critical
CVE-2019-15929
was published
for
craftcms/cms
(Composer)
May 24, 2022
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without...
Moderate
Unreviewed
CVE-2019-15749
was published
May 24, 2022
In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to...
Moderate
Unreviewed
CVE-2019-14955
was published
May 24, 2022
TTLock devices do not properly restrict password-reset attempts, leading to incorrect access...
High
Unreviewed
CVE-2019-12943
was published
May 24, 2022
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is...
Moderate
Unreviewed
CVE-2019-13240
was published
May 24, 2022
An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress...
High
Unreviewed
CVE-2019-10270
was published
May 24, 2022
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover)...
Critical
Unreviewed
CVE-2018-16988
was published
May 24, 2022
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is...
High
Unreviewed
CVE-2019-11414
was published
May 24, 2022
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged...
Critical
Unreviewed
CVE-2019-11393
was published
May 24, 2022
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049...
High
Unreviewed
CVE-2016-5996
was published
May 17, 2022
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049...
Moderate
Unreviewed
CVE-2016-5997
was published
May 17, 2022
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom...
Critical
Unreviewed
CVE-2017-2766
was published
May 17, 2022
Craft CMS subject to URL forgery
Moderate
CVE-2017-8385
was published
for
craftcms/cms
(Composer)
May 17, 2022
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows...
High
Unreviewed
CVE-2017-7731
was published
May 17, 2022
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
High
Unreviewed
CVE-2017-7629
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API