GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,752
Maven
4,982
npm
3,516
NuGet
609
pip
3,090
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
93 advisories
Filter by severity
Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc....
High
Unreviewed
CVE-2024-5862
was published
Jun 24, 2024
eZ Platform Admin UI Password reset vulnerability
High
GHSA-hfpp-2vhw-qq43
was published
for
ezsystems/ezplatform-user
(Composer)
May 15, 2024
eZ Platform Password reset vulnerability
High
GHSA-cg84-55jx-4237
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
May 15, 2024
CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability
High
CVE-2024-24767
was published
for
github.com/IceWhaleTech/CasaOS-UserService
(Go)
Mar 6, 2024
An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb...
High
Unreviewed
CVE-2024-1104
was published
Feb 22, 2024
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting...
High
Unreviewed
CVE-2023-45191
was published
Feb 9, 2024
IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting...
High
Unreviewed
CVE-2023-38273
was published
Feb 2, 2024
IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a...
High
Unreviewed
CVE-2023-50326
was published
Feb 2, 2024
The Omron FINS protocol has an authenticated feature to prevent access to memory regions....
High
Unreviewed
CVE-2022-45790
was published
Jan 22, 2024
The number of attempts to bring the Hozard Alarm system (alarmsystemen) v1.0 to a disarmed state...
High
Unreviewed
CVE-2023-50123
was published
Jan 11, 2024
WWBN AVideo Improper Restriction of Excessive Authentication Attempts vulnerability
High
CVE-2023-49810
was published
for
wwbn/avideo
(Composer)
Jan 10, 2024
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an...
High
Unreviewed
CVE-2023-6912
was published
Dec 20, 2023
By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI...
High
Unreviewed
CVE-2023-50444
was published
Dec 13, 2023
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple...
High
Unreviewed
CVE-2023-41350
was published
Nov 3, 2023
A lack of rate limiting in Elenos ETG150 FM transmitter v3.12 allows attackers to obtain user...
High
Unreviewed
CVE-2023-37832
was published
Oct 31, 2023
generator-jhipster allows a timing attack against validateToken due to a string comparison that stops at the first character
High
CVE-2015-20110
was published
for
generator-jhipster
(npm)
Oct 31, 2023
The TETRA TEA1 keystream generator implements a key register initialization function that...
High
Unreviewed
CVE-2022-24402
was published
Oct 19, 2023
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation...
High
Unreviewed
CVE-2023-44111
was published
Oct 11, 2023
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation...
High
Unreviewed
CVE-2023-44096
was published
Oct 11, 2023
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU
allows an...
High
Unreviewed
CVE-2023-43699
was published
Oct 9, 2023
IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) uses an...
High
Unreviewed
CVE-2023-26271
was published
Aug 28, 2023
IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to...
High
Unreviewed
CVE-2022-43904
was published
Aug 28, 2023
Weintek Weincloud v0.13.6
could allow an attacker to efficiently develop a brute force...
High
Unreviewed
CVE-2023-32657
was published
Jul 20, 2023
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and...
High
Unreviewed
CVE-2023-29301
was published
Jul 12, 2023
SAP BusinessObjects Business Intelligence Platform - version 420, 430, allows an unauthorized...
High
Unreviewed
CVE-2023-36917
was published
Jul 11, 2023
ProTip!
Advisories are also available from the
GraphQL API