GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,815
Erlang
36
GitHub Actions
32
Go
2,401
Maven
5,000+
npm
4,044
NuGet
723
pip
3,830
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
88 advisories
Filter by severity
Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and...
High
Unreviewed
CVE-2025-31965
was published
Jul 29, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
Authentication vulnerability in the distributed collaboration framework module
Impact: Successful...
Moderate
Unreviewed
CVE-2025-53167
was published
Jul 7, 2025
File Browser's password protection of links is bypassable
Low
CVE-2025-52996
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by...
Critical
Unreviewed
CVE-2025-46801
was published
May 19, 2025
OPKSSH Vulnerable to Authentication Bypass
Critical
CVE-2025-4658
was published
for
github.com/openpubkey/opkssh
(Go)
May 13, 2025
OpenPubkey Vulnerable to Authentication Bypass
Critical
CVE-2025-3757
was published
for
github.com/openpubkey/openpubkey
(Go)
May 13, 2025
SEL BIOS packages prior to 1.3.49152.117 or 2.6.49152.98 allow a local attacker to bypass...
Moderate
Unreviewed
CVE-2025-46750
was published
May 12, 2025
KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a...
Critical
Unreviewed
CVE-2025-32011
was published
May 2, 2025
KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured...
Critical
Unreviewed
CVE-2025-24522
was published
May 2, 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the...
Critical
Unreviewed
CVE-2025-31161
was published
Apr 3, 2025
The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and...
Moderate
Unreviewed
CVE-2025-31192
was published
Apr 1, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and...
Moderate
Unreviewed
CVE-2025-30428
was published
Apr 1, 2025
In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password...
High
Unreviewed
CVE-2024-12776
was published
Mar 20, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42513
was published
for
OPCFoundation.NetStandard.Opc.Ua.Bindings.Https
(NuGet)
Mar 3, 2025
In certain IETF OAuth 2.0-related specifications, when the JSON Web Token Profile for OAuth 2.0...
Moderate
Unreviewed
CVE-2025-27371
was published
Mar 3, 2025
OpenID Connect Core through 1.0 errata set 2 allows audience injection in certain situations....
Moderate
Unreviewed
CVE-2025-27370
was published
Mar 3, 2025
WorkOS Hosted AuthKit before 2025-01-07 allows a password authentication MFA bypass (by enrolling...
Moderate
Unreviewed
CVE-2025-23017
was published
Feb 24, 2025
ZF Roll Stability Support Plus (RSSPlus)
is vulnerable to an authentication bypass vulnerability...
Moderate
Unreviewed
CVE-2024-12054
was published
Feb 14, 2025
Duplicate Advisory: Authentication Bypass by Spoofing in OPC UA .NET Standard Stack
Moderate
GHSA-7wwr-h8cm-9jf7
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Feb 10, 2025
•
withdrawn
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling...
Critical
Unreviewed
CVE-2024-12802
was published
Jan 9, 2025
Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows...
Moderate
Unreviewed
CVE-2023-46611
was published
Jan 2, 2025
Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful...
Moderate
Unreviewed
CVE-2022-48470
was published
Dec 28, 2024
A flaw was found in the skupper console, a read-only interface that renders cluster network,...
High
Unreviewed
CVE-2024-12582
was published
Dec 24, 2024
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all...
Critical
Unreviewed
CVE-2021-26102
was published
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API