GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
207 advisories
Filter by severity
The Dingtian DT-R0 Series is vulnerable to an exploit that allows
attackers to bypass login...
Critical
Unreviewed
CVE-2025-1283
was published
Feb 14, 2025
Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
High
CVE-2025-26511
was published
for
com.instaclustr:cassandra-lucene-index-plugin
(Maven)
Feb 13, 2025
The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2024-13182
was published
Feb 13, 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting...
High
Unreviewed
CVE-2025-24472
was published
Feb 11, 2025
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover...
Critical
Unreviewed
CVE-2025-0181
was published
Feb 11, 2025
The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-0316
was published
Feb 9, 2025
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-1061
was published
Feb 7, 2025
Multiple Elber products are affected by an authentication bypass
vulnerability which allows...
Critical
Unreviewed
CVE-2025-0674
was published
Feb 7, 2025
Mitmweb API Authentication Bypass Using Proxy Server
High
CVE-2025-23217
was published
for
mitmproxy
(pip)
Feb 6, 2025
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2025-0364
was published
Feb 4, 2025
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to,...
Critical
Unreviewed
CVE-2024-12857
was published
Jan 22, 2025
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication...
Moderate
Unreviewed
CVE-2025-24456
was published
Jan 21, 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting...
Critical
Unreviewed
CVE-2024-55591
was published
Jan 14, 2025
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A...
Critical
Unreviewed
CVE-2024-12847
was published
Jan 10, 2025
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is...
Critical
Unreviewed
CVE-2024-12402
was published
Jan 7, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS allows...
Critical
Unreviewed
CVE-2024-56044
was published
Dec 31, 2024
IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By...
Moderate
Unreviewed
CVE-2024-51464
was published
Dec 21, 2024
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to,...
Critical
Unreviewed
CVE-2024-11349
was published
Dec 21, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in Envato Security Team...
Critical
Unreviewed
CVE-2024-43234
was published
Dec 16, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in Wovax, LLC. Wovax IDX...
High
Unreviewed
CVE-2024-56013
was published
Dec 16, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in Projectopia Projectopia...
High
Unreviewed
CVE-2024-54336
was published
Dec 13, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in appgenixinfotech...
Critical
Unreviewed
CVE-2024-54294
was published
Dec 13, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in www.vbsso.com vBSSO...
Critical
Unreviewed
CVE-2024-54297
was published
Dec 13, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in InspireUI ListApp...
Critical
Unreviewed
CVE-2024-54295
was published
Dec 13, 2024
ProTip!
Advisories are also available from the
GraphQL API