GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,413
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,656
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
152 advisories
Filter by severity
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting...
High
Unreviewed
CVE-2026-31851
was published
Mar 23, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-31904
was published
Mar 21, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-31903
was published
Mar 21, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-20882
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-24696
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on the number of...
High
Unreviewed
CVE-2026-27778
was published
Mar 6, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-24445
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-26305
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25114
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25945
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-20792
was published
Feb 27, 2026
The WebSocket Application Programming Interface lacks restrictions on
the number of...
High
Unreviewed
CVE-2026-25113
was published
Feb 27, 2026
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Feb 13, 2026
Moodle Affected by Improper Restriction of Excessive Authentication Attempts
High
CVE-2025-67853
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
This vulnerability arises because there are no limitations on the number
of authentication...
High
Unreviewed
CVE-2025-53968
was published
Jan 23, 2026
Dell PowerScale OneFS versions prior to 9.13.0.0 contains an improper restriction of excessive...
High
Unreviewed
CVE-2026-22278
was published
Jan 22, 2026
In affected versions, vulnerability-lookup did not track or limit failed
One-Time Password (OTP)...
High
Unreviewed
CVE-2025-42615
was published
Dec 8, 2025
Dell CloudBoost Virtual Appliance, versions 19.13.0.0 and prior, contains an Improper Restriction...
High
Unreviewed
CVE-2025-46603
was published
Dec 5, 2025
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force...
High
Unreviewed
CVE-2025-12995
was published
Dec 4, 2025
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit...
High
Unreviewed
CVE-2025-63807
was published
Nov 20, 2025
Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side...
High
Unreviewed
CVE-2025-10161
was published
Nov 11, 2025
Zitadel allows brute-forcing authentication factors
High
CVE-2025-64102
was published
for
github.com/zitadel/zitadel
(Go)
Oct 29, 2025
Moodle vulnerable to brute-force password guesses
High
CVE-2025-62399
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via...
High
Unreviewed
CVE-2025-8679
was published
Oct 1, 2025
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with...
High
Unreviewed
CVE-2025-35041
was published
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API