GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
188 advisories
Filter by severity
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by...
Moderate
Unreviewed
CVE-2024-8692
was published
Sep 11, 2024
Django Potential account hijack via password reset form
Critical
CVE-2019-19844
was published
for
Django
(pip)
Jan 16, 2020
Indico Tampering with links (e.g. password reset) in sent emails
High
CVE-2021-30185
was published
for
indico
(pip)
Apr 8, 2021
A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password...
High
Unreviewed
CVE-2024-45980
was published
Sep 26, 2024
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205,...
High
Unreviewed
CVE-2023-42481
was published
Dec 12, 2023
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an...
Critical
Unreviewed
CVE-2024-8878
was published
Sep 25, 2024
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability...
Moderate
Unreviewed
CVE-2024-9907
was published
Oct 13, 2024
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation...
High
Unreviewed
CVE-2024-9305
was published
Oct 16, 2024
The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is...
High
Unreviewed
CVE-2024-9302
was published
Oct 25, 2024
IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their...
Moderate
Unreviewed
CVE-2024-45670
was published
Nov 14, 2024
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password...
Critical
Unreviewed
CVE-2024-48428
was published
Oct 25, 2024
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in...
Critical
Unreviewed
CVE-2021-22763
was published
May 24, 2022
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows...
Critical
Unreviewed
CVE-2023-36487
was published
Jun 29, 2023
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable...
High
Unreviewed
CVE-2023-29145
was published
Jun 30, 2023
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account...
Critical
Unreviewed
CVE-2024-11103
was published
Nov 28, 2024
This issue was addressed with improved state management. This issue is fixed in iOS 16.5 and...
Moderate
Unreviewed
CVE-2023-28202
was published
Jun 23, 2023
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for...
Critical
Unreviewed
CVE-2024-47547
was published
Dec 6, 2024
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2022-42807
was published
Jun 23, 2023
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account...
Critical
Unreviewed
CVE-2024-53552
was published
Dec 10, 2024
Keycloak Denial of Service via account lockout
Low
CVE-2024-1722
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 12, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16...
Critical
Unreviewed
CVE-2023-7028
was published
Jan 12, 2024
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in...
Critical
Unreviewed
CVE-2024-11350
was published
Jan 8, 2025
A vulnerability, which was classified as critical, has been found in YunzMall up to 2.4.2. This...
Moderate
Unreviewed
CVE-2025-0331
was published
Jan 9, 2025
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM)...
High
Unreviewed
CVE-2018-8916
was published
May 13, 2022
Missing rate limit for password resets
Moderate
CVE-2023-28821
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
ProTip!
Advisories are also available from the
GraphQL API