GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
77 advisories
Filter by severity
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Moderate
CVE-2025-58065
was published
for
flask-appbuilder
(pip)
Sep 11, 2025
Salt has minion event bus authorization bypass vulnerability
High
CVE-2025-22236
was published
for
salt
(pip)
Jun 13, 2025
Salt's salt.auth.pki module does not properly authenticate callers
Moderate
CVE-2024-38825
was published
for
salt
(pip)
Jun 13, 2025
CKAN contains Improper Authentication leading to account takeover
High
CVE-2022-43685
was published
for
ckan
(pip)
Nov 22, 2022
OpenStack Identity (Keystone) Trustee token revocations does not work with memcache backend
High
CVE-2014-2237
was published
for
keystone
(pip)
May 17, 2022
Saltstack Salt Unauthenticated Arbitrary Code Execution
High
CVE-2021-25315
was published
for
salt
(pip)
May 24, 2022
Moderate severity vulnerability that affects Products.PlonePAS
Moderate
CVE-2009-0662
was published
for
Products.PlonePAS
(pip)
Jul 23, 2018
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
High
CVE-2024-8053
was published
for
open-webui
(pip)
Mar 20, 2025
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
Improper Authentication in Flask-AppBuilder
High
CVE-2021-41265
was published
for
Flask-AppBuilder
(pip)
Dec 9, 2021
Sentry's improper authentication on SAML SSO process allows user impersonation
Critical
CVE-2025-22146
was published
for
sentry
(pip)
Jan 15, 2025
OpenStack Keystone Improper Authentication vulnerability
Moderate
CVE-2013-1865
was published
for
keystone
(pip)
May 17, 2022
OpenStack Identity (Keystone) DoS through V3 API authentication chaining
High
CVE-2014-2828
was published
for
keystone
(pip)
May 17, 2022
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
Moderate
CVE-2013-2059
was published
for
keystone
(pip)
May 17, 2022
Zope Object Database (ZODB) Authentication bypass in ZEO storage servers
High
CVE-2009-0669
was published
for
ZODB3
(pip)
May 2, 2022
Trytond allows modification of privileges of arbitrary users
High
CVE-2012-0215
was published
for
trytond
(pip)
May 4, 2022
cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes
Critical
CVE-2024-47533
was published
for
cobbler
(pip)
Nov 18, 2024
Indy's NODE_UPGRADE transaction vulnerable to remote code execution
High
CVE-2022-31020
was published
for
indy-node
(pip)
Sep 2, 2022
Ansible password prompts could expose passwords
High
CVE-2019-14856
was published
for
ansible
(pip)
May 24, 2022
Potential bypass of an upstream access control based on URL paths in Django
Moderate
CVE-2021-44420
was published
for
Django
(pip)
Dec 9, 2021
OpenStack Swauth object/proxy server writing Auth Token to log file
Critical
CVE-2017-16613
was published
for
swauth
(pip)
May 17, 2022
Improper Authentication in SaltStack Salt
High
CVE-2021-22004
was published
for
salt
(pip)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API