GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
159 advisories
Filter by severity
Authentication Bypass by Capture-replay in Apache Spark
High
CVE-2021-38296
was published
for
org.apache.spark:spark-core
(Maven)
Mar 11, 2022
An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an...
Critical
Unreviewed
CVE-2023-49231
was published
Mar 29, 2024
A remote authentication bypass issue exists in some
OneView APIs.
Critical
Unreviewed
CVE-2023-30909
was published
Sep 14, 2023
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service...
High
Unreviewed
CVE-2024-22066
was published
Oct 29, 2024
Hyperledger Fabric does not verify request has a timestamp within the expected time window
Moderate
CVE-2024-45244
was published
for
github.com/hyperledger/fabric
(Go)
Aug 25, 2024
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against...
Low
Unreviewed
CVE-2024-36250
was published
Nov 9, 2024
@strapi/plugin-users-permissions leaks 3rd party authentication tokens and authentication bypass
High
CVE-2024-34065
was published
for
@strapi/plugin-users-permissions
(npm)
Jun 12, 2024
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by...
High
Unreviewed
CVE-2024-49595
was published
Nov 26, 2024
In the development options section of the Settings app, there is a possible authentication bypass...
High
Unreviewed
CVE-2018-9477
was published
Nov 20, 2024
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay...
Moderate
Unreviewed
CVE-2024-52534
was published
Dec 25, 2024
The login mechanism via device authentication of CGFIDO from Changing Information Technology has...
High
Unreviewed
CVE-2024-12839
was published
Dec 31, 2024
IO FinNet tss-lib vulnerable to replay attacks involving proofs
Moderate
CVE-2022-47930
was published
for
github.com/binance-chain/tss-lib
(Go)
Apr 21, 2023
Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote...
Critical
Unreviewed
CVE-2025-26201
was published
Feb 24, 2025
SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This...
High
Unreviewed
CVE-2025-1887
was published
Mar 7, 2025
Microsoft Outlook Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2023-23397
was published
Mar 14, 2023
Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028...
High
Unreviewed
CVE-2024-12137
was published
Mar 19, 2025
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which...
High
Unreviewed
CVE-2024-40715
was published
Nov 7, 2024
Replay Attack
in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows...
Critical
Unreviewed
CVE-2024-4009
was published
Jun 5, 2024
The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass...
Moderate
Unreviewed
CVE-2022-43704
was published
Jan 20, 2023
An OpenPGP digital signature includes information about the date when the signature was created....
Moderate
Unreviewed
CVE-2022-2226
was published
Dec 22, 2022
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix ...
Critical
Unreviewed
CVE-2021-27289
was published
Apr 15, 2025
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force...
Critical
Unreviewed
CVE-2021-22640
was published
Jul 29, 2022
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level...
High
Unreviewed
CVE-2017-6823
was published
May 13, 2022
An Authentication Bypass by Capture-Replay issue was discovered in Schneider Electric Modicon...
Critical
Unreviewed
CVE-2017-6034
was published
May 13, 2022
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to...
Critical
Unreviewed
CVE-2017-3191
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API