GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            176 advisories
        Filter by severity
        
      
      
    
                    
                      Moodle does not properly enforce MFA
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62398
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Oct 23, 2025 
                    
                  
                    
                      MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11287
                      
                      was published
                        for
                        
                          @samanhappy/mcphub
                        
                        (npm)
                      Oct 5, 2025 
                    
                  
                    
                      Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59347
                      
                      was published
                        for
                        
                          d7y.io/dragonfly/v2
                        
                        (Go)
                      Sep 17, 2025 
                    
                  
                    
                      Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-58065
                      
                      was published
                        for
                        
                          flask-appbuilder
                        
                        (pip)
                      Sep 11, 2025 
                    
                  
                    
                      Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53889
                      
                      was published
                        for
                        
                          directus
                        
                        (npm)
                      Jul 15, 2025 
                    
                  
                    
                      Salt's salt.auth.pki module does not properly authenticate callers
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-38825
                      
                      was published
                        for
                        
                          salt
                        
                        (pip)
                      Jun 13, 2025 
                    
                  
                    
                      Pekko Management may not properly apply authenticator when Basic Authentication enabled
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-46548
                      
                      was published
                        for
                        
                          com.lightbend.akka.management:akka-management_2.12
                        
                        (Maven)
                      Jun 3, 2025 
                    
                  
                    
                      @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-4144
                      
                      was published
                        for
                        
                          @cloudflare/workers-oauth-provider
                        
                        (npm)
                      May 1, 2025 
                    
                  
                    
                      Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
                    
                      
  Moderate
                    
                
                      
                        GHSA-vh4h-fvqf-q9wv
                      
                      was published
                        for
                        
                          @cloudflare/workers-oauth-provider
                        
                        (npm)
                      May 1, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Keycloak vulnerable to two factor authentication bypass
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3910
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-services
                        
                        (Maven)
                      Apr 30, 2025 
                    
                  
                    
                      Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass
                    
                      
  Moderate
                    
                
                      
                        GHSA-fx44-2wx5-5fvp
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-services
                        
                        (Maven)
                      Apr 29, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Moodle makes some user data available before completing second factor with MFA enabled
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3627
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Apr 25, 2025 
                    
                  
                    
                      Moodle self enrollment available before completing second factor with MFA enabled
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3634
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Apr 25, 2025 
                    
                  
                    
                      Parse Server has an OAuth login vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-30168
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Mar 21, 2025 
                    
                  
                    
                      Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-29773
                      
                      was published
                        for
                        
                          froxlor/froxlor
                        
                        (Composer)
                      Mar 11, 2025 
                    
                  
                    
                      Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-0604
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-ldap-federation
                        
                        (Maven)
                      Mar 10, 2025 
                    
                  
                    
                      MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-27414
                      
                      was published
                        for
                        
                          github.com/minio/minio
                        
                        (Go)
                      Mar 3, 2025 
                    
                  
                    
                      Navidrome allows an authentication bypass in Subsonic API with non-existent username
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-27112
                      
                      was published
                        for
                        
                          github.com/navidrome/navidrome
                        
                        (Go)
                      Feb 25, 2025 
                    
                  
                    
                      Duplicate Advisory: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak 
                    
                      
  Moderate
                    
                
                      
                        GHSA-m3hp-8546-5qmr
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-ldap-federation
                        
                        (Maven)
                      Jan 22, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-36402
                      
                      was published
                        for
                        
                          github.com/t2bot/matrix-media-repo
                        
                        (Go)
                      Jan 16, 2025 
                    
                  
                    
                      Withdrawn Advisory: Symfony http-security has authentication bypass
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-36611
                      
                      was published
                        for
                        
                          symfony/security-http
                        
                        (Composer)
                      Nov 29, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Re-creating a deleted user in lakeFS will re-enable previous user credentials that existed prior to its deletion
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-43784
                      
                      was published
                        for
                        
                          github.com/treeverse/lakefs
                        
                        (Go)
                      Nov 26, 2024 
                    
                  
                    
                      Ory Kratos's setting required_aal `highest_available` does not properly respect code + mfa credentials
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-45042
                      
                      was published
                        for
                        
                          github.com/ory/kratos
                        
                        (Go)
                      Sep 26, 2024 
                    
                  
                    
                      OpenDaylight Authentication, Authorization and Accounting (AAA) peer impersonation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-46943
                      
                      was published
                        for
                        
                          org.opendaylight.aaa:aaa-artifacts
                        
                        (Maven)
                      Sep 16, 2024 
                    
                  
                    
                      Eclipse Dataspace Components's ConsumerPullTransferTokenValidationApiController doesn't check for token validit
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-8642
                      
                      was published
                        for
                        
                          org.eclipse.edc:transfer-data-plane
                        
                        (Maven)
                      Sep 11, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API