GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
198 advisories
Filter by severity
Authentication Bypass Using an Alternate Path or Channel vulnerability in Projectopia Projectopia...
High
Unreviewed
CVE-2024-54336
was published
Dec 13, 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server...
Critical
Unreviewed
CVE-2023-42793
was published
Sep 19, 2023
Authentication Bypass Using an Alternate Path or Channel vulnerability in Wovax, LLC. Wovax IDX...
High
Unreviewed
CVE-2024-56013
was published
Dec 16, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in Envato Security Team...
Critical
Unreviewed
CVE-2024-43234
was published
Dec 16, 2024
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to,...
Critical
Unreviewed
CVE-2024-11349
was published
Dec 21, 2024
IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By...
Moderate
Unreviewed
CVE-2024-51464
was published
Dec 21, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS allows...
Critical
Unreviewed
CVE-2024-56044
was published
Dec 31, 2024
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is...
Critical
Unreviewed
CVE-2024-12402
was published
Jan 7, 2025
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A...
Critical
Unreviewed
CVE-2024-12847
was published
Jan 10, 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting...
Critical
Unreviewed
CVE-2024-55591
was published
Jan 14, 2025
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote...
Critical
Unreviewed
CVE-2024-11639
was published
Dec 10, 2024
Even if the authentication fails for local service authentication, the requested command could...
Critical
Unreviewed
CVE-2022-46732
was published
Jan 18, 2023
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects...
High
Unreviewed
CVE-2024-7125
was published
Aug 27, 2024
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version...
High
Unreviewed
CVE-2024-47574
was published
Nov 13, 2024
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to,...
Critical
Unreviewed
CVE-2024-12857
was published
Jan 22, 2025
The web server of affected devices do not properly authenticate user request to the '/ClientArea...
Moderate
Unreviewed
CVE-2024-46887
was published
Oct 8, 2024
Undisclosed requests may bypass configuration utility authentication, allowing an attacker...
Critical
Unreviewed
CVE-2023-46747
was published
Oct 26, 2023
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-9861
was published
Oct 17, 2024
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
Critical
Unreviewed
CVE-2024-10284
was published
Nov 9, 2024
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication...
Moderate
Unreviewed
CVE-2025-24456
was published
Jan 21, 2025
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2025-0364
was published
Feb 4, 2025
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary...
High
Unreviewed
CVE-2023-21098
was published
Apr 19, 2023
ProTip!
Advisories are also available from the
GraphQL API