GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
21 advisories
Filter by severity
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions <...
Critical
Unreviewed
CVE-2022-43400
was published
Oct 21, 2022
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation...
Critical
Unreviewed
CVE-2024-0822
was published
Jan 25, 2024
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate...
Critical
Unreviewed
CVE-2024-38182
was published
Aug 1, 2024
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011,...
Critical
Unreviewed
CVE-2023-49340
was published
Mar 9, 2024
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection...
Critical
Unreviewed
CVE-2024-34451
was published
Jun 17, 2024
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication,...
Critical
Unreviewed
CVE-2023-39439
was published
Aug 8, 2023
The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication...
Critical
Unreviewed
CVE-2024-45367
was published
Oct 4, 2024
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication...
Critical
Unreviewed
CVE-2024-13239
was published
Jan 9, 2025
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0...
Critical
Unreviewed
CVE-2024-48886
was published
Jan 14, 2025
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing...
Critical
Unreviewed
CVE-2025-1387
was published
Feb 17, 2025
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in...
Critical
Unreviewed
CVE-2024-39848
was published
Jun 30, 2024
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions),...
Critical
Unreviewed
CVE-2024-54092
was published
Apr 8, 2025
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP allows Privilege Escalation. This...
Critical
Unreviewed
CVE-2025-39596
was published
Apr 17, 2025
Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission...
Critical
Unreviewed
CVE-2024-0949
was published
Jun 27, 2024
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing...
Critical
Unreviewed
CVE-2025-12870
was published
Nov 12, 2025
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing...
Critical
Unreviewed
CVE-2025-12871
was published
Nov 12, 2025
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by...
Critical
Unreviewed
CVE-2023-53894
was published
Dec 16, 2025
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability...
Critical
Unreviewed
CVE-2025-40554
was published
Jan 28, 2026
Sensitive data disclosure and manipulation due to improper authentication. The following products...
Critical
Unreviewed
CVE-2025-30412
was published
Feb 20, 2026
Sensitive data disclosure and manipulation due to improper authentication. The following products...
Critical
Unreviewed
CVE-2025-30411
was published
Feb 20, 2026
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability...
Critical
Unreviewed
CVE-2025-40552
was published
Jan 28, 2026
ProTip!
Advisories are also available from the
GraphQL API