GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            21 advisories
        Filter by severity
        
      
      
    
                    
                      Authentication bypass in Apache Airflow
                    
                      
  Critical
                    
                
                      
                        CVE-2020-13927
                      
                      was published
                        for
                        
                          apache-airflow
                        
                        (pip)
                      Apr 30, 2021 
                    
                  
                    
                      Missing authentication in ShenYu
                    
                      
  Critical
                    
                
                      
                        CVE-2022-23944
                      
                      was published
                        for
                        
                          org.apache.shenyu:shenyu-common
                        
                        (Maven)
                      Jan 28, 2022 
                    
                  
                    
                      Remote code execution in Apache TomEE
                    
                      
  Critical
                    
                
                      
                        CVE-2020-13931
                      
                      was published
                        for
                        
                          org.apache.tomee:apache-tomee
                        
                        (Maven)
                      Feb 9, 2022 
                    
                  
                    
                      Improper Authentication in Apache Spark
                    
                      
  Critical
                    
                
                      
                        CVE-2020-9480
                      
                      was published
                        for
                        
                          org.apache.spark:spark-parent_2.11
                        
                        (Maven)
                      Feb 10, 2022 
                    
                  
                    
                      Missing Authentication for Critical Function in Apache Cassandra
                    
                      
  Critical
                    
                
                      
                        CVE-2018-8016
                      
                      was published
                        for
                        
                          org.apache.cassandra:cassandra-all
                        
                        (Maven)
                      May 13, 2022 
                    
                  
                    
                      SaltStack Salt Unauthenticated Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2020-11651
                      
                      was published
                        for
                        
                          salt
                        
                        (pip)
                      May 24, 2022 
                    
                  
                    
                      DevSpace vulnerable to remote code execution
                    
                      
  Critical
                    
                
                      
                        CVE-2020-15391
                      
                      was published
                        for
                        
                          github.com/loft-sh/devspace
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Missing Authentication for Critical Function in Apache Airflow
                    
                      
  Critical
                    
                
                      
                        CVE-2021-38540
                      
                      was published
                        for
                        
                          apache-airflow
                        
                        (pip)
                      May 24, 2022 
                    
                  
                    
                      Rdiffweb is missing authentication for critical function
                    
                      
  Critical
                    
                
                      
                        CVE-2022-3327
                      
                      was published
                        for
                        
                          rdiffweb
                        
                        (pip)
                      Oct 20, 2022 
                    
                  
                    
                      Apache SOAP contains unauthenticated RPCRouterServlet
                    
                      
  Critical
                    
                
                      
                        CVE-2022-45378
                      
                      was published
                        for
                        
                          soap:soap
                        
                        (Maven)
                      Nov 14, 2022 
                    
                  
                    
                      KubeView vulnerable to full cluster takeover due to improper authentication
                    
                      
  Critical
                    
                
                      
                        CVE-2022-45933
                      
                      was published
                        for
                        
                          github.com/benc-uk/kubeview
                        
                        (Go)
                      Nov 27, 2022 
                    
                  
                    
                      Apache OpenMeetings missing authentication and can allow user impersonation 
                    
                      
  Critical
                    
                
                      
                        CVE-2023-28326
                      
                      was published
                        for
                        
                          org.apache.openmeetings:openmeetings-parent
                        
                        (Maven)
                      Mar 28, 2023 
                    
                  
                    
                      CasaOS Gateway vulnerable to incorrect identification of source IP addresses
                    
                      
  Critical
                    
                
                      
                        CVE-2023-37265
                      
                      was published
                        for
                        
                          github.com/IceWhaleTech/CasaOS-Gateway
                        
                        (Go)
                      Jul 17, 2023 
                    
                  
                    
                      sing-box vulnerable to improper authentication in the SOCKS inbound
                    
                      
  Critical
                    
                
                      
                        CVE-2023-43644
                      
                      was published
                        for
                        
                          github.com/sagernet/sing
                        
                        (Go)
                      Sep 26, 2023 
                    
                  
                    
                      Jupyter Server Proxy's Websocket Proxying does not require authentication
                    
                      
  Critical
                    
                
                      
                        CVE-2024-28179
                      
                      was published
                        for
                        
                          jupyter-server-proxy
                        
                        (pip)
                      Mar 20, 2024 
                    
                  
                    
                      Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
                    
                      
  Critical
                    
                
                      
                        GHSA-c995-4fw3-j39m
                      
                      was published
                        for
                        
                          langflow
                        
                        (pip)
                      Apr 7, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      BackendAI Missing Authentication for Critical Function
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49652
                      
                      was published
                        for
                        
                          backend.ai
                        
                        (pip)
                      Jun 9, 2025 
                    
                  
                    
                      MCP Inspector proxy server lacks authentication between the Inspector client and proxy
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49596
                      
                      was published
                        for
                        
                          @modelcontextprotocol/inspector
                        
                        (npm)
                      Jun 13, 2025 
                    
                  
                    
                      Flowise OS command remote code execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-8943
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Aug 14, 2025 
                    
                  
                    
                      Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58434
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 12, 2025 
                    
                  
                    
                      Better Auth: Unauthenticated API key creation through api-key plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61928
                      
                      was published
                        for
                        
                          better-auth
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API