GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
109 advisories
Filter by severity
An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is...
High
Unreviewed
CVE-2021-27935
was published
May 24, 2022
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a...
High
Unreviewed
CVE-2021-27188
was published
May 24, 2022
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement...
High
Unreviewed
CVE-2021-3138
was published
May 24, 2022
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force...
High
Unreviewed
CVE-2020-35585
was published
May 24, 2022
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using...
High
Unreviewed
CVE-2020-35586
was published
May 24, 2022
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows...
High
Unreviewed
CVE-2020-27423
was published
May 24, 2022
OATHAuth extension in MediaWiki is not implementing rate limit
High
CVE-2020-25827
was published
for
mediawiki/core
(Composer)
May 24, 2022
A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS...
High
Unreviewed
CVE-2020-15786
was published
May 24, 2022
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel...
High
Unreviewed
CVE-2020-13872
was published
May 24, 2022
Pimcore Discloses Usernames In Use
High
CVE-2019-18986
was published
for
pimcore/pimcore
(Composer)
May 24, 2022
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a...
High
Unreviewed
CVE-2019-4520
was published
May 24, 2022
Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of...
High
Unreviewed
CVE-2019-3746
was published
May 24, 2022
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout...
High
Unreviewed
CVE-2019-4310
was published
May 24, 2022
The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an...
High
Unreviewed
CVE-2019-14951
was published
May 24, 2022
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration,...
High
Unreviewed
CVE-2019-4068
was published
May 24, 2022
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 ...
High
Unreviewed
CVE-2022-24044
was published
May 21, 2022
htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through...
High
Unreviewed
CVE-2017-14423
was published
May 13, 2022
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could...
High
Unreviewed
CVE-2017-12316
was published
May 13, 2022
Keycloak Improper Bruteforce Detection
High
CVE-2018-14657
was published
for
org.keycloak:keycloak-parent
(Maven)
May 13, 2022
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The...
High
Unreviewed
CVE-2019-0039
was published
May 13, 2022
SaltStack RSA Key Generation allows remote users to decrypt communications
High
CVE-2013-2228
was published
for
salt
(pip)
May 5, 2022
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
High
Unreviewed
CVE-2013-2257
was published
May 5, 2022
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when...
High
Unreviewed
CVE-2001-1339
was published
Apr 30, 2022
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect...
High
Unreviewed
CVE-2001-1291
was published
Apr 30, 2022
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which...
High
Unreviewed
CVE-2001-0395
was published
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API