GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
40 advisories
Filter by severity
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password...
Critical
Unreviewed
CVE-2024-48428
was published
Oct 25, 2024
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an...
Critical
Unreviewed
CVE-2024-8878
was published
Sep 25, 2024
Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the...
Critical
Unreviewed
CVE-2024-38468
was published
Jun 16, 2024
An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak...
Critical
Unreviewed
CVE-2024-5404
was published
Jun 3, 2024
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS...
Critical
Unreviewed
CVE-2023-30466
was published
Apr 28, 2023
The default setting of MISP 2.4.136 did not enable the requirements (aka...
Critical
Unreviewed
CVE-2021-25323
was published
May 24, 2022
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover)...
Critical
Unreviewed
CVE-2018-16988
was published
May 24, 2022
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged...
Critical
Unreviewed
CVE-2019-11393
was published
May 24, 2022
ZPanel 10.0.1 has insufficient entropy for its password reset process.
Critical
Unreviewed
CVE-2012-5686
was published
Apr 23, 2022
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16...
Critical
Unreviewed
CVE-2023-7028
was published
Jan 12, 2024
An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password...
Critical
Unreviewed
CVE-2021-41694
was published
Dec 10, 2021
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android...
Critical
Unreviewed
CVE-2022-45637
was published
Mar 21, 2023
The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker...
Critical
Unreviewed
CVE-2023-0352
was published
Mar 13, 2023
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks...
Critical
Unreviewed
CVE-2017-7551
was published
May 14, 2022
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A...
Critical
Unreviewed
CVE-2022-45782
was published
Feb 2, 2023
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that...
Critical
Unreviewed
CVE-2017-17097
was published
May 14, 2022
CMS Made Simple (CMSMS) through 2.2.6 contains an admin password reset vulnerability because data...
Critical
Unreviewed
CVE-2018-10081
was published
May 14, 2022
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that...
Critical
Unreviewed
CVE-2022-37300
was published
Sep 13, 2022
Instant Update CMS contains a Password Reset Vulnerability vulnerability in /iu-application...
Critical
Unreviewed
CVE-2018-1000501
was published
May 14, 2022
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password ...
Critical
Unreviewed
CVE-2018-12421
was published
May 14, 2022
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in...
Critical
Unreviewed
CVE-2018-1000554
was published
May 14, 2022
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings...
Critical
Unreviewed
CVE-2018-17881
was published
May 14, 2022
An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon...
Critical
Unreviewed
CVE-2018-7809
was published
May 14, 2022
An issue was discovered in Enalean Tuleap before 10.5. Reset password links are not invalidated...
Critical
Unreviewed
CVE-2018-17298
was published
May 14, 2022
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset...
Critical
Unreviewed
CVE-2015-4689
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API