GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,857
Maven
5,000+
npm
4,488
NuGet
780
pip
4,243
Pub
12
RubyGems
975
Rust
1,095
Swift
49
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Soft Serve Affected by an Authentication Bypass
High
CVE-2026-24058
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 21, 2026
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow...
High
Unreviewed
CVE-2025-55130
was published
Jan 20, 2026
A flaw was found in Keycloak. An IDOR (Broken Access Control) vulnerability exists in the admin...
Moderate
Unreviewed
CVE-2025-14777
was published
Dec 16, 2025
The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions...
Critical
Unreviewed
CVE-2025-13613
was published
Dec 10, 2025
authentik allows a deactivated Service account to authenticate to OAuth
Moderate
CVE-2025-64521
was published
for
goauthentik.io
(Go)
Nov 19, 2025
The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login...
High
Unreviewed
CVE-2025-60375
was published
Oct 9, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network...
Moderate
Unreviewed
CVE-2025-8415
was published
Aug 20, 2025
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root...
Critical
Unreviewed
CVE-2025-29266
was published
Mar 31, 2025
The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
High
Unreviewed
CVE-2024-11283
was published
Mar 14, 2025
Moodle Lesson activity password bypass through PHP loose comparison
Moderate
CVE-2024-45691
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
Symfony has an Authentication Bypass via RememberMe
High
CVE-2024-51996
was published
for
symfony/security-http
(Composer)
Nov 13, 2024
Missing key verification in gost
Critical
CVE-2024-39223
was published
for
github.com/ginuerzh/gost
(Go)
Jul 3, 2024
Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards,...
Moderate
Unreviewed
CVE-2024-34519
was published
May 6, 2024
Hail relies on OIDC email claims to verify the validity of a user's domain.
Moderate
CVE-2023-51663
was published
for
hail
(pip)
Jan 2, 2024
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
High
CVE-2023-41890
was published
for
Kentor.AuthServices
(NuGet)
Sep 20, 2023
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to...
High
Unreviewed
CVE-2023-3263
was published
Aug 14, 2023
Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware...
Critical
Unreviewed
CVE-2023-1803
was published
Apr 14, 2023
Authentication Bypass by Alternate Name in Apache Tomcat
Moderate
CVE-2021-30640
was published
for
org.apache.tomcat:tomcat
(Maven)
Aug 13, 2021
ProTip!
Advisories are also available from the
GraphQL API