GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
109 advisories
Filter by severity
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration,...
High
Unreviewed
CVE-2019-4068
was published
May 24, 2022
htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through...
High
Unreviewed
CVE-2017-14423
was published
May 13, 2022
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could...
High
Unreviewed
CVE-2017-12316
was published
May 13, 2022
IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting...
High
Unreviewed
CVE-2021-38890
was published
Nov 24, 2021
IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a...
High
Unreviewed
CVE-2019-4520
was published
May 24, 2022
If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The...
High
Unreviewed
CVE-2019-0039
was published
May 13, 2022
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout...
High
Unreviewed
CVE-2019-4310
was published
May 24, 2022
The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission...
High
Unreviewed
CVE-2022-37144
was published
Sep 9, 2022
The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts...
High
Unreviewed
CVE-2022-37145
was published
Sep 9, 2022
The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network...
High
Unreviewed
CVE-2022-23746
was published
Nov 30, 2022
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts...
High
Unreviewed
CVE-2022-37772
was published
Nov 23, 2022
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on...
High
Unreviewed
CVE-2021-22003
was published
May 24, 2022
IBM Security Guardium 11.2 uses an inadequate account lockout setting that could allow a remote...
High
Unreviewed
CVE-2021-20427
was published
May 24, 2022
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and...
High
Unreviewed
CVE-2021-27943
was published
May 24, 2022
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to...
High
Unreviewed
CVE-2021-35472
was published
May 24, 2022
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker...
High
Unreviewed
CVE-2020-23283
was published
May 24, 2022
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
High
Unreviewed
CVE-2021-28127
was published
May 24, 2022
It was found that all versions of 3Scale developer portal lacked brute force protections. An...
High
Unreviewed
CVE-2021-3412
was published
May 24, 2022
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device, able to...
High
Unreviewed
CVE-2020-26556
was published
May 24, 2022
A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE...
High
Unreviewed
CVE-2021-25676
was published
May 24, 2022
In Solstice Pod before 3.3.0 (or Open4.3), the Administrator password can be enumerated using...
High
Unreviewed
CVE-2020-35586
was published
May 24, 2022
The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a...
High
Unreviewed
CVE-2021-27188
was published
May 24, 2022
In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement...
High
Unreviewed
CVE-2021-3138
was published
May 24, 2022
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows...
High
Unreviewed
CVE-2020-27423
was published
May 24, 2022
In Solstice Pod before 3.3.0 (or Open4.3), the screen key can be enumerated using brute-force...
High
Unreviewed
CVE-2020-35585
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API