GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,334
Maven
5,000+
npm
3,967
NuGet
713
pip
3,763
Pub
12
RubyGems
923
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
117 advisories
Filter by severity
Password guessing limits could be bypassed when using LDAP authentication.
High
Unreviewed
CVE-2025-48014
was published
May 20, 2025
An unauthenticated user could discover account credentials via a brute-force attack without rate...
High
Unreviewed
CVE-2025-46739
was published
May 12, 2025
This vulnerability exists in Meon KYC solutions due to missing restrictions on the number of...
High
Unreviewed
CVE-2025-42600
was published
Apr 23, 2025
Lack of protection against brute force attacks in Valmet DNA visualization in DNA Operate. The...
High
Unreviewed
CVE-2025-0417
was published
Apr 1, 2025
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email...
High
Unreviewed
CVE-2025-31676
was published
Apr 1, 2025
langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the...
High
Unreviewed
CVE-2024-12039
was published
Mar 20, 2025
IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote...
High
Unreviewed
CVE-2024-51476
was published
Mar 6, 2025
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version...
High
Unreviewed
CVE-2024-23106
was published
Jan 14, 2025
JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where...
High
Unreviewed
CVE-2024-55008
was published
Jan 7, 2025
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of...
High
Unreviewed
CVE-2024-49597
was published
Nov 26, 2024
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2024-5716
was published
Nov 22, 2024
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential...
High
Unreviewed
CVE-2024-7292
was published
Oct 9, 2024
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0...
High
Unreviewed
CVE-2024-45327
was published
Sep 11, 2024
A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout...
High
Unreviewed
CVE-2021-22530
was published
Aug 28, 2024
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an...
High
Unreviewed
CVE-2024-39398
was published
Aug 14, 2024
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions ...
High
Unreviewed
CVE-2024-41904
was published
Aug 13, 2024
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly...
High
Unreviewed
CVE-2024-38888
was published
Aug 2, 2024
An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated...
High
Unreviewed
CVE-2024-38176
was published
Jul 24, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1)....
High
Unreviewed
CVE-2024-39873
was published
Jul 9, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1)....
High
Unreviewed
CVE-2024-39874
was published
Jul 9, 2024
Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc....
High
Unreviewed
CVE-2024-5862
was published
Jun 24, 2024
eZ Platform Admin UI Password reset vulnerability
High
GHSA-hfpp-2vhw-qq43
was published
for
ezsystems/ezplatform-user
(Composer)
May 15, 2024
eZ Platform Password reset vulnerability
High
GHSA-cg84-55jx-4237
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
May 15, 2024
ZITADEL's Improper Lockout Mechanism Leads to MFA Bypass
High
CVE-2024-32868
was published
for
github.com/zitadel/zitadel
(Go)
Apr 25, 2024
ProTip!
Advisories are also available from the
GraphQL API