GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
246 advisories
Filter by severity
Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to...
High
Unreviewed
CVE-2017-11786
was published
May 13, 2022
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass...
Moderate
Unreviewed
CVE-2018-16242
was published
May 13, 2022
YSoft SafeQ Server 6 allows a replay attack.
High
Unreviewed
CVE-2018-15498
was published
May 13, 2022
The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same...
High
Unreviewed
CVE-2022-38766
was published
Jan 3, 2023
The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is...
Moderate
Unreviewed
CVE-2021-46145
was published
Jan 7, 2022
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an...
Critical
Unreviewed
CVE-2022-22806
was published
Mar 10, 2022
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for...
High
Unreviewed
CVE-2021-39364
was published
Feb 25, 2022
GoAhead before 5.1.2 mishandles the nonce value during Digest authentication. This may permit...
Moderate
Unreviewed
CVE-2020-15688
was published
May 24, 2022
The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF...
Moderate
Unreviewed
CVE-2022-45914
was published
Nov 27, 2022
Multi-Factor Authentication issue in Laravel Fortify
High
CVE-2022-25838
was published
for
laravel/fortify
(Composer)
Feb 25, 2022
Answer vulnerable to Authentication Bypass by Capture-replay
Critical
CVE-2023-1537
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application...
Moderate
Unreviewed
CVE-2019-11334
was published
May 24, 2022
thorsten/phpmyfaq vulnerable to authentication bypass
High
CVE-2023-1886
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Capture-replay in Gitea
Critical
CVE-2021-45327
was published
for
github.com/go-gitea/gitea
(Go)
Feb 9, 2022
A vulnerability in the offline access mode of Cisco Duo Two-Factor Authentication for macOS and...
Moderate
Unreviewed
CVE-2023-20123
was published
Apr 5, 2023
Authentication Bypass in hydra
Moderate
CVE-2020-5300
was published
for
github.com/ory/hydra
(Go)
May 27, 2021
Authentication bypass by capture-replay in github.com/cosmos/ethermint
High
CVE-2021-25835
was published
for
github.com/cosmos/ethermint
(Go)
Feb 15, 2022
Authentication bypass by capture-replay in github.com/cosmos/ethermint
High
CVE-2021-25834
was published
for
github.com/cosmos/ethermint
(Go)
Feb 15, 2022
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4...
Moderate
Unreviewed
CVE-2023-45794
was published
Nov 14, 2023
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X...
High
Unreviewed
CVE-2023-39547
was published
Nov 17, 2023
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor with man-in...
High
Unreviewed
CVE-2023-20900
was published
Aug 31, 2023
Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3...
High
Unreviewed
CVE-2022-46480
was published
Dec 5, 2023
The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical...
Moderate
Unreviewed
CVE-2023-50128
was published
Jan 11, 2024
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC...
Moderate
Unreviewed
CVE-2023-6374
was published
Jan 30, 2024
The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to...
High
Unreviewed
CVE-2023-46892
was published
Jan 23, 2024
ProTip!
Advisories are also available from the
GraphQL API