GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,090
Erlang
29
GitHub Actions
19
Go
1,915
Maven
5,000+
npm
3,646
NuGet
638
pip
3,262
Pub
10
RubyGems
870
Rust
821
Swift
35
Unreviewed advisories
All unreviewed
5,000+
156 advisories
Filter by severity
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Moderate
CVE-2022-23541
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
Keycloak vulnerable to session takeover with OIDC offline refreshtokens
Moderate
CVE-2022-3916
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 13, 2022
Authentication Bypass for passport-wsfed-saml2
Moderate
CVE-2022-23505
was published
for
passport-wsfed-saml2
(npm)
Dec 13, 2022
TYPO3 CMS vulnerable to Weak Authentication in Frontend Login
Moderate
CVE-2022-23501
was published
for
typo3/cms
(Composer)
Dec 13, 2022
Prometheus Exporter-Toolkit is vulnerable to authentication bypass
Moderate
CVE-2022-46146
was published
for
github.com/prometheus/exporter-toolkit
(Go)
Dec 2, 2022
Concrete CMS vulnerable to Improper Authentication
Moderate
CVE-2022-43690
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
Lin CMS vulnerable to Improper Authentication
Moderate
CVE-2022-44244
was published
for
Lin-CMS
(Maven)
Nov 10, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
Moderate
CVE-2022-39252
was published
for
matrix-sdk-crypto
(Rust)
Sep 30, 2022
Upstash Adapter missing token verification
Moderate
CVE-2022-39263
was published
for
@next-auth/upstash-redis-adapter
(npm)
Sep 30, 2022
Moodle type juggling vulnerability
Moderate
CVE-2021-40693
was published
for
moodle/moodle
(Composer)
Sep 30, 2022
Snipe-IT vulnerable to Improper Authentication
Moderate
CVE-2022-3173
was published
for
snipe/snipe-it
(Composer)
Sep 18, 2022
TYPO3 CMS missing check for expiration time of password reset token for backend users
Moderate
CVE-2022-36106
was published
for
typo3/cms
(Composer)
Sep 16, 2022
Indy's NODE_UPGRADE transaction vulnerable to remote code execution
Moderate
CVE-2022-31020
was published
for
indy-node
(pip)
Sep 2, 2022
JetBrain Ktor before 2.1.0 vulnerable to selection of wrong authentication provider
Moderate
CVE-2022-38180
was published
for
io.ktor:ktor
(Maven)
Aug 13, 2022
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Moderate
CVE-2015-5298
was published
for
org.jenkins-ci.plugins:google-login
(Maven)
Jul 8, 2022
Unpublished, protected files can be published via shortcode
Moderate
CVE-2022-29858
was published
for
silverstripe/assets
(Composer)
Jun 29, 2022
Limited Authentication Bypass for Media Files
Moderate
CVE-2022-29237
was published
for
org.opencastproject:opencast-ingest-service-impl
(Maven)
May 25, 2022
Improper Authentication in SaltStack Salt
Moderate
CVE-2021-22004
was published
for
salt
(pip)
May 24, 2022
Keycloak discloses information without authentication
Moderate
CVE-2020-27838
was published
for
org.keycloak:keycloak-core
(Maven)
May 24, 2022
Ansible password prompts could expose passwords
Moderate
CVE-2019-14856
was published
for
ansible
(pip)
May 24, 2022
Magento Broken authentication and session managememt
Moderate
CVE-2019-8108
was published
for
magento/community-edition
(Composer)
May 24, 2022
Improper Authentication in Apache MyFaces
Moderate
CVE-2010-2057
was published
for
org.apache.myfaces.core:myfaces-impl
(Maven)
May 17, 2022
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
Moderate
CVE-2012-6431
was published
for
symfony/http-foundation
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API