GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,966 advisories
Filter by severity
Moodle does not properly enforce MFA
Moderate
CVE-2025-62398
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper...
Critical
Unreviewed
CVE-2025-43995
was published
Oct 24, 2025
Captive Portal can allow authentication bypass
High
Unreviewed
CVE-2025-6979
was published
Oct 23, 2025
Mattermost Server: Insufficient Password-Reset Link Invalidation
High
CVE-2016-11074
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Authentication bypass for viewing and deletions of snapshots
High
CVE-2021-39226
was published
for
github.com/grafana/grafana
(Go)
Oct 5, 2021
Account Takeover in Octobercms
High
CVE-2021-32648
was published
for
october/system
(Composer)
Aug 30, 2021
Authentication bypass in Apache Airflow
Critical
CVE-2020-13927
was published
for
apache-airflow
(pip)
Apr 30, 2021
Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017,...
Critical
Unreviewed
CVE-2025-60772
was published
Oct 21, 2025
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
Critical
Unreviewed
CVE-2025-56447
was published
Oct 22, 2025
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote...
Moderate
Unreviewed
CVE-2013-0625
was published
May 17, 2022
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component:...
Critical
Unreviewed
CVE-2025-61882
was published
Oct 5, 2025
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to perform...
Moderate
Unreviewed
CVE-2025-49706
was published
Jul 8, 2025
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code...
High
Unreviewed
CVE-2025-3935
was published
Apr 25, 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote...
Critical
Unreviewed
CVE-2024-53704
was published
Jan 9, 2025
Remote command execution due to use of default passwords. The following products are affected:...
Critical
Unreviewed
CVE-2023-45249
was published
Jul 24, 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1...
Critical
Unreviewed
CVE-2024-7593
was published
Aug 13, 2024
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication...
Critical
Unreviewed
CVE-2024-8956
was published
Sep 17, 2024
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient...
Moderate
Unreviewed
CVE-2024-37085
was published
Jun 25, 2024
Microsoft Exchange Server Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2024-21410
was published
Feb 13, 2024
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti...
High
Unreviewed
CVE-2023-46805
was published
Jan 12, 2024
Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, through 11.10 allows remote...
Critical
Unreviewed
CVE-2023-35078
was published
Jul 25, 2023
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest...
Low
Unreviewed
CVE-2023-20867
was published
Jun 13, 2023
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users...
Critical
Unreviewed
CVE-2023-35082
was published
Aug 15, 2023
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An...
Critical
Unreviewed
CVE-2023-28461
was published
Mar 16, 2023
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code...
Critical
Unreviewed
CVE-2021-44515
was published
Dec 13, 2021
ProTip!
Advisories are also available from the
GraphQL API