GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,801 advisories
Filter by severity
Improper authentication vulnerability in the communication protocol provided by AD (Automation...
Critical
Unreviewed
CVE-2022-26034
was published
Apr 16, 2022
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it...
Moderate
Unreviewed
CVE-2010-2496
was published
Apr 21, 2022
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05...
Critical
Unreviewed
CVE-2021-44971
was published
Jan 29, 2022
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in...
Moderate
Unreviewed
CVE-2021-46249
was published
Feb 17, 2022
ECP SAML binding bypasses authentication flows
High
CVE-2021-3827
was published
for
org.keycloak:keycloak-saml-core
(Maven)
Apr 27, 2022
A business logic vulnerability exists in Mi App Store. The vulnerability is caused by incomplete...
Moderate
Unreviewed
CVE-2020-14121
was published
Apr 22, 2022
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD...
High
Unreviewed
CVE-2017-2871
was published
May 13, 2022
An exploitable vulnerability exists in the generation of authentication token functionality of...
Critical
Unreviewed
CVE-2017-2864
was published
May 13, 2022
Improper Authentication in Mortbay Jetty
High
CVE-2007-5614
was published
for
org.mortbay.jetty:jetty
(Maven)
May 1, 2022
Improper Authentication in Apache Kafka
Moderate
CVE-2017-12610
was published
for
org.apache.kafka:kafka-clients
(Maven)
May 13, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2013-2067
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Authentication in Spring Security
High
CVE-2014-0097
was published
for
org.springframework.security:spring-security-core
(Maven)
May 13, 2022
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney...
High
Unreviewed
CVE-2017-2914
was published
May 13, 2022
Limited Authentication Bypass for Media Files
Moderate
CVE-2022-29237
was published
for
org.opencastproject:opencast-ingest-service-impl
(Maven)
May 25, 2022
A denial of service vulnerability exists in the SeaMax remote configuration functionality of...
High
Unreviewed
CVE-2021-21965
was published
Feb 10, 2022
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a...
Critical
Unreviewed
CVE-2012-10001
was published
Apr 23, 2022
Improper Authentication in Apache Hadoop
Moderate
CVE-2014-0229
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
Improper Authentication in OpenSAML
Moderate
CVE-2011-1411
was published
for
org.opensaml:opensaml
(Maven)
May 17, 2022
Improper Authentication in Apache Qpid
Moderate
CVE-2012-4446
was published
for
org.apache.qpid:qpid-client
(Maven)
May 17, 2022
Improper Authentication in Apache Axis2
Moderate
CVE-2012-5351
was published
for
org.apache.axis2:axis2
(Maven)
May 13, 2022
Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD...
High
Unreviewed
CVE-2017-2872
was published
May 13, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2012-5887
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
An authentication bypass vulnerability exists in the process_msg() function of the home_security...
High
Unreviewed
CVE-2021-21953
was published
Dec 23, 2021
Improper Authentication in Jenkins
Moderate
CVE-2017-2604
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an...
Moderate
Unreviewed
CVE-2021-21133
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API