GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,896 advisories
Filter by severity
An attacker with access to the network where the vulnerable device is located could capture...
Moderate
Unreviewed
CVE-2025-2859
was published
Mar 28, 2025
CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability...
Critical
Unreviewed
CVE-2025-2825
was published
Mar 26, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2746
was published
Mar 24, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2747
was published
Mar 24, 2025
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker...
High
Unreviewed
CVE-2024-57490
was published
Mar 21, 2025
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
High
CVE-2024-8053
was published
for
open-webui
(pip)
Mar 20, 2025
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that...
Moderate
Unreviewed
CVE-2024-12869
was published
Mar 20, 2025
Spring Security Does Not Enforce Password Length
High
CVE-2025-22228
was published
for
org.springframework.security:spring-security-crypto
(Maven)
Mar 20, 2025
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore...
Moderate
Unreviewed
CVE-2025-26475
was published
Mar 19, 2025
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device...
Critical
Unreviewed
CVE-2025-30114
was published
Mar 18, 2025
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of...
High
Unreviewed
CVE-2025-30116
was published
Mar 18, 2025
A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by...
Moderate
Unreviewed
CVE-2025-2388
was published
Mar 17, 2025
A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash...
Moderate
Unreviewed
CVE-2025-2344
was published
Mar 16, 2025
A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This...
Moderate
Unreviewed
CVE-2025-2339
was published
Mar 16, 2025
A flaw exists in the Windows login flow where an AuthContext token can
be exploited for replay...
High
Unreviewed
CVE-2025-2230
was published
Mar 13, 2025
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass...
High
Unreviewed
CVE-2025-0813
was published
Mar 12, 2025
Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
Moderate
CVE-2025-29773
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Ratify Azure authentication providers can leak authentication tokens to non-Azure container registries
High
CVE-2025-27403
was published
for
github.com/deislabs/ratify
(Go)
Mar 11, 2025
A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning...
Critical
Unreviewed
CVE-2024-56336
was published
Mar 11, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Mar 10, 2025
Improper Authentication vulnerability in GE Vernova EnerVista UR Setup allows Authentication...
High
Unreviewed
CVE-2025-27254
was published
Mar 10, 2025
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin...
High
Unreviewed
CVE-2024-11087
was published
Mar 8, 2025
The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up...
Critical
Unreviewed
CVE-2025-1475
was published
Mar 7, 2025
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to...
Moderate
Unreviewed
CVE-2025-25452
was published
Mar 6, 2025
ProTip!
Advisories are also available from the
GraphQL API