GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,161
Erlang
30
GitHub Actions
19
Go
1,966
Maven
5,000+
npm
3,694
NuGet
653
pip
3,311
Pub
11
RubyGems
881
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
164 advisories
Filter by severity
The N-central server is vulnerable to an authentication bypass of the user interface. This...
Critical
Unreviewed
CVE-2024-28200
was published
Jul 1, 2024
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
Critical
CVE-2024-39309
was published
for
parse-server
(npm)
Jul 1, 2024
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks...
Critical
Unreviewed
CVE-2024-2973
was published
Jun 27, 2024
IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive...
High
Unreviewed
CVE-2024-31916
was published
Jun 27, 2024
Firefly III has a MFA bypass in oauth flow
Moderate
CVE-2024-37893
was published
for
grumpydictator/firefly-iii
(Composer)
Jun 17, 2024
An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to...
Critical
Unreviewed
CVE-2023-37057
was published
Jun 17, 2024
Attackers can bypass the web login authentication process to gain access to the printer's system...
High
Unreviewed
CVE-2024-3496
was published
Jun 14, 2024
The affected product is vulnerable to an attacker modifying the bootloader by using custom...
Moderate
Unreviewed
CVE-2024-38279
was published
Jun 13, 2024
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /
API Gateway...
Critical
Unreviewed
CVE-2024-2013
was published
Jun 11, 2024
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker...
Critical
Unreviewed
CVE-2024-2012
was published
Jun 11, 2024
Silverpeas authentication bypass
Critical
CVE-2024-36042
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Jun 3, 2024
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local...
High
Unreviewed
CVE-2024-29853
was published
May 23, 2024
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise...
Critical
Unreviewed
CVE-2024-29849
was published
May 23, 2024
An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access...
High
Unreviewed
CVE-2022-32503
was published
May 14, 2024
In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by...
Critical
Unreviewed
CVE-2024-34524
was published
May 6, 2024
Keycloak secondary factor bypass in step-up authentication
Moderate
CVE-2023-3597
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over...
High
Unreviewed
CVE-2024-1646
was published
Apr 16, 2024
TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login...
High
Unreviewed
CVE-2024-31814
was published
Apr 8, 2024
An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an...
Critical
Unreviewed
CVE-2023-49231
was published
Mar 29, 2024
An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the...
High
Unreviewed
CVE-2024-26566
was published
Mar 7, 2024
Services that are running and bound to the loopback interface on the Artica Proxy are accessible...
Unknown
Unreviewed
CVE-2024-2056
was published
Mar 5, 2024
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management...
Critical
Unreviewed
CVE-2024-2055
was published
Mar 5, 2024
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions...
Critical
Unreviewed
CVE-2024-27198
was published
Mar 4, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16...
Moderate
Unreviewed
CVE-2024-1525
was published
Feb 22, 2024
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an...
Critical
Unreviewed
CVE-2024-1709
was published
Feb 21, 2024
ProTip!
Advisories are also available from the
GraphQL API