GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
873 advisories
Filter by severity
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings...
Critical
Unreviewed
CVE-2021-46742
was published
Apr 12, 2022
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24...
Critical
Unreviewed
CVE-2021-45507
was published
Dec 27, 2021
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin...
Critical
Unreviewed
CVE-2021-44526
was published
Dec 24, 2021
Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24...
Critical
Unreviewed
CVE-2021-45509
was published
Dec 27, 2021
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows...
Critical
Unreviewed
CVE-2021-29396
was published
Feb 9, 2022
NETGEAR R6700v2 devices before 1.2.0.88 are affected by authentication bypass.
Critical
Unreviewed
CVE-2021-45498
was published
Dec 27, 2021
NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.
Critical
Unreviewed
CVE-2021-45497
was published
Dec 27, 2021
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC)...
Critical
Unreviewed
CVE-2022-20695
was published
Apr 16, 2022
ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via ...
Critical
Unreviewed
CVE-2022-25226
was published
Apr 19, 2022
Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus,...
Critical
Unreviewed
CVE-2021-29655
was published
Feb 19, 2022
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious...
Critical
Unreviewed
CVE-2021-31932
was published
Feb 12, 2022
Argo CD will blindly trust JWT claims if anonymous access is enabled
Critical
CVE-2022-29165
was published
for
github.com/argoproj/argo-cd
(Go)
May 24, 2022
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE...
Critical
Unreviewed
CVE-2022-22955
was published
Apr 14, 2022
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9...
Critical
Unreviewed
CVE-2021-44757
was published
Jan 19, 2022
Improper authentication vulnerability in the communication protocol provided by AD (Automation...
Critical
Unreviewed
CVE-2022-26034
was published
Apr 16, 2022
Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05...
Critical
Unreviewed
CVE-2021-44971
was published
Jan 29, 2022
An exploitable vulnerability exists in the generation of authentication token functionality of...
Critical
Unreviewed
CVE-2017-2864
was published
May 13, 2022
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a...
Critical
Unreviewed
CVE-2012-10001
was published
Apr 23, 2022
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7,...
Critical
Unreviewed
CVE-2021-27215
was published
May 24, 2022
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication...
Critical
Unreviewed
CVE-2020-25218
was published
May 24, 2022
NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.
Critical
Unreviewed
CVE-2021-29065
was published
May 24, 2022
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation...
Critical
Unreviewed
CVE-2021-3325
was published
May 24, 2022
The impacted products, when configured to use SSO, are affected by an improper authentication...
Critical
Unreviewed
CVE-2021-43935
was published
Dec 16, 2021
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the...
Critical
Unreviewed
CVE-2021-21986
was published
May 24, 2022
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and...
Critical
Unreviewed
CVE-2020-13963
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API