GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,328
NuGet
761
pip
4,100
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,544 advisories
Filter by severity
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator...
High
Unreviewed
CVE-2021-3297
was published
May 24, 2022
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
High
GHSA-v5w9-prxf-w882
was published
for
flowise
(npm)
Nov 17, 2025
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
High
CVE-2025-64717
was published
for
github.com/zitadel/zitadel
(Go)
Nov 14, 2025
TYPO3 Modules Extension has Improper Authentication vulnerability
High
CVE-2025-12998
was published
for
codingms/modules
(Composer)
Nov 12, 2025
Zitadel May Bypass Second Authentication Factor
High
CVE-2025-64103
was published
for
github.com/zitadel/zitadel
(Go)
Oct 29, 2025
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD)...
High
Unreviewed
CVE-2023-52161
was published
Feb 22, 2024
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP...
High
Unreviewed
CVE-2025-49812
was published
Jul 10, 2025
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate...
High
Unreviewed
CVE-2023-45866
was published
Dec 8, 2023
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an...
High
Unreviewed
CVE-2022-4874
was published
Jan 11, 2023
Mesh Provisioning in the Bluetooth Mesh profile 1.0 and 1.0.1 may permit a nearby device (without...
High
Unreviewed
CVE-2020-26557
was published
May 24, 2022
Apache ActiveMQ Deserialization of Untrusted Data vulnerability
High
CVE-2022-41678
was published
for
org.apache.activemq:apache-activemq
(Maven)
Nov 28, 2023
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker...
High
Unreviewed
CVE-2020-4427
was published
May 24, 2022
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension...
High
Unreviewed
CVE-2025-6926
was published
Jul 3, 2025
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local...
High
Unreviewed
CVE-2025-0217
was published
May 5, 2025
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26...
High
Unreviewed
CVE-2025-31271
was published
Sep 16, 2025
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local...
High
Unreviewed
CVE-2023-23632
was published
Oct 12, 2023
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the...
High
Unreviewed
CVE-2022-0996
was published
Mar 24, 2022
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This...
High
Unreviewed
CVE-2025-41110
was published
Oct 22, 2025
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
High
GHSA-c2jp-c369-7pvx
was published
for
fastmcp
(pip)
Oct 29, 2025
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web...
High
Unreviewed
CVE-2025-9063
was published
Oct 14, 2025
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing...
High
Unreviewed
CVE-2025-9064
was published
Oct 14, 2025
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2...
High
Unreviewed
CVE-2025-60424
was published
Oct 27, 2025
Captive Portal can allow authentication bypass
High
Unreviewed
CVE-2025-6979
was published
Oct 23, 2025
Mattermost Server: Insufficient Password-Reset Link Invalidation
High
CVE-2016-11074
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API