GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
139 advisories
Filter by severity
Windu CMS implements weak client-side brute-force protection by using parameter loginError....
Moderate
Unreviewed
CVE-2025-59113
was published
Nov 18, 2025
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that...
Moderate
Unreviewed
CVE-2025-11566
was published
Nov 12, 2025
Improper resource management in firmware of some Solidigm DC Products may allow an attacker with...
Moderate
Unreviewed
CVE-2025-12896
was published
Nov 7, 2025
A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability...
Moderate
Unreviewed
CVE-2025-12547
was published
Oct 31, 2025
Liferay Portal vulnerable to password enumeration
Moderate
CVE-2025-62257
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 30, 2025
Drupal Access code allows Brute Force Attempts
Moderate
CVE-2025-10928
was published
for
drupal/access_code
(Composer)
Oct 30, 2025
A security vulnerability has been detected in VirtFusion up to 6.0.2. This vulnerability affects...
Moderate
Unreviewed
CVE-2025-12310
was published
Oct 27, 2025
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8...
Moderate
Unreviewed
CVE-2025-56224
was published
Oct 20, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages...
Moderate
Unreviewed
CVE-2025-9551
was published
Oct 11, 2025
A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown...
Moderate
Unreviewed
CVE-2025-11441
was published
Oct 8, 2025
The application does not implement sufficient measures to prevent multiple failed authentication...
Moderate
Unreviewed
CVE-2025-58587
was published
Oct 6, 2025
PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count...
Moderate
Unreviewed
CVE-2025-8118
was published
Sep 30, 2025
IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate...
Moderate
Unreviewed
CVE-2025-36064
was published
Sep 22, 2025
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-10658
was published
Sep 22, 2025
A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api...
Moderate
Unreviewed
CVE-2025-10761
was published
Sep 22, 2025
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in...
Moderate
Unreviewed
CVE-2025-54860
was published
Sep 19, 2025
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the...
Moderate
Unreviewed
CVE-2025-36758
was published
Sep 10, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing...
Moderate
Unreviewed
CVE-2025-9004
was published
Aug 15, 2025
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2025-8927
was published
Aug 13, 2025
A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by...
Moderate
Unreviewed
CVE-2025-8742
was published
Aug 9, 2025
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Moderate
CVE-2025-55003
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Moderate
CVE-2025-54998
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Moderate
CVE-2025-6015
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Moderate
CVE-2025-6004
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
ProTip!
Advisories are also available from the
GraphQL API