GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
42 advisories
Filter by severity
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
Low
CVE-2024-56128
was published
for
org.apache.kafka:kafka_2.10
(Maven)
Dec 18, 2024
A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66...
High
Unreviewed
CVE-2025-44557
was published
Jun 27, 2025
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow...
High
Unreviewed
CVE-2021-42146
was published
Jan 24, 2024
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Moderate
CVE-2025-48994
was published
for
signxml
(pip)
Jun 5, 2025
Mattermost fails to properly invalidate personal access tokens upon user deactivation
Moderate
CVE-2025-3230
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost fails to clear Google OAuth credentials
Moderate
CVE-2025-2571
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Moderate
CVE-2025-2475
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 14, 2025
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer...
High
Unreviewed
CVE-2016-9463
was published
May 13, 2022
Saltstack Salt Unauthenticated Arbitrary Code Execution
High
CVE-2021-25315
was published
for
salt
(pip)
May 24, 2022
An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses...
Moderate
Unreviewed
CVE-2024-8314
was published
Mar 25, 2025
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE...
High
Unreviewed
CVE-2024-34722
was published
Jul 9, 2024
Windows NTLM V1 Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2025-21311
was published
Jan 14, 2025
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11...
Critical
Unreviewed
CVE-2024-10127
was published
Nov 20, 2024
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against...
Low
Unreviewed
CVE-2024-36250
was published
Nov 9, 2024
In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication...
Moderate
Unreviewed
CVE-2024-9999
was published
Nov 12, 2024
Mattermost incorrectly issues two sessions when using desktop SSO
Low
CVE-2024-10214
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Oct 28, 2024
Eclipse Dataspace Components's ConsumerPullTransferTokenValidationApiController doesn't check for token validit
Moderate
CVE-2024-8642
was published
for
org.eclipse.edc:transfer-data-plane
(Maven)
Sep 11, 2024
social-auth-app-django affected by Improper Handling of Case Sensitivity
Moderate
CVE-2024-32879
was published
for
social-auth-app-django
(pip)
Apr 24, 2024
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows...
Moderate
Unreviewed
CVE-2022-4861
was published
Dec 30, 2022
Insufficient authentication flow in Checkmk before 2.2.0p17, 2.1.0p37 and 2.0.0p39 allows...
High
Unreviewed
CVE-2023-31211
was published
Jan 12, 2024
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with...
Moderate
Unreviewed
CVE-2024-25157
was published
Aug 14, 2024
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space...
Low
Unreviewed
CVE-2024-41829
was published
Jul 22, 2024
Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote...
Critical
Unreviewed
CVE-2023-4860
was published
Jul 17, 2024
An authentication bypass vulnerability has been identified in the REST and SOAP API components of...
Unknown
Unreviewed
CVE-2024-4332
was published
Jun 3, 2024
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when...
Critical
Unreviewed
CVE-2024-4985
was published
May 21, 2024
ProTip!
Advisories are also available from the
GraphQL API