GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
162 advisories
Filter by severity
Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover...
Critical
Unreviewed
CVE-2021-28293
was published
May 24, 2022
Multiple valid tokens for password reset in Shopware
Moderate
CVE-2022-24892
was published
for
shopware/shopware
(Composer)
Apr 28, 2022
Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13...
Critical
Unreviewed
CVE-2022-47377
was published
Dec 21, 2022
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3,...
High
Unreviewed
CVE-2021-33321
was published
May 24, 2022
In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows...
High
Unreviewed
CVE-2021-36708
was published
May 24, 2022
In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
Critical
Unreviewed
CVE-2021-36209
was published
May 24, 2022
Malicious attacker is able to find out valid user logins by using the "lost password" feature....
Moderate
Unreviewed
CVE-2021-36095
was published
May 24, 2022
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The...
Critical
Unreviewed
CVE-2018-16529
was published
Apr 30, 2022
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application...
High
Unreviewed
CVE-2016-8716
was published
May 13, 2022
In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute...
Moderate
Unreviewed
CVE-2021-39899
was published
May 24, 2022
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to...
High
Unreviewed
CVE-2021-25961
was published
May 24, 2022
An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of...
Critical
Unreviewed
CVE-2022-44004
was published
Nov 17, 2022
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers...
High
Unreviewed
CVE-2022-25027
was published
Jan 13, 2023
Improper account password reset in Craft CMS
High
CVE-2022-29933
was published
for
craftcms/cms
(Composer)
May 10, 2022
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to...
High
Unreviewed
CVE-2017-9543
was published
May 13, 2022
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with...
Critical
Unreviewed
CVE-2018-18871
was published
May 13, 2022
Weak Password Recovery Mechanism for Forgotten Password
High
CVE-2021-25957
was published
for
dolibarr/dolibarr
(Composer)
Sep 2, 2021
Malicious password-reset in Akaunting
High
CVE-2021-36804
was published
for
akaunting/akaunting
(Composer)
Sep 1, 2021
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
High
Unreviewed
CVE-2021-44037
was published
Nov 20, 2021
In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from...
Moderate
Unreviewed
CVE-2021-39919
was published
Dec 14, 2021
Unverified password change vulnerability in Change Password in Synology DiskStation Manager (DSM)...
High
Unreviewed
CVE-2018-8916
was published
May 13, 2022
When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to...
Moderate
Unreviewed
CVE-2017-2614
was published
May 13, 2022
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web...
High
Unreviewed
CVE-2017-14005
was published
May 13, 2022
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to...
High
Unreviewed
CVE-2017-8613
was published
May 13, 2022
Missing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change...
Moderate
Unreviewed
CVE-2018-12315
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API