GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
169 advisories
Filter by severity
@cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
CVE-2025-4144
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
GHSA-vh4h-fvqf-q9wv
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Keycloak vulnerable to two factor authentication bypass
Moderate
CVE-2025-3910
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass
Moderate
GHSA-fx44-2wx5-5fvp
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 29, 2025
•
withdrawn
Moodle makes some user data available before completing second factor with MFA enabled
Moderate
CVE-2025-3627
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle self enrollment available before completing second factor with MFA enabled
Moderate
CVE-2025-3634
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism
Moderate
CVE-2014-6288
was published
for
in2code/powermail
(Composer)
May 17, 2022
Moodle Session Fixation vulnerability
Moderate
CVE-2010-1613
was published
for
moodle/moodle
(Composer)
May 13, 2022
TYPO3 Install Tool Subcomponent Allows Access Using Only a Password's MD5 Hash as a Credential
Moderate
CVE-2009-3635
was published
for
typo3/cms
(Composer)
May 2, 2022
Moderate severity vulnerability that affects Products.PlonePAS
Moderate
CVE-2009-0662
was published
for
Products.PlonePAS
(pip)
Jul 23, 2018
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
Keycloak vulnerable to session hijacking via re-authentication
Moderate
CVE-2023-6787
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
Moderate
CVE-2025-29773
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Jenkins does not Restrict Reserved Names Allowing for Privilege Escalation
Moderate
CVE-2015-1810
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Duplicate Advisory: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
GHSA-m3hp-8546-5qmr
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Jan 22, 2025
•
withdrawn
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Mar 10, 2025
MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
Moderate
CVE-2025-27414
was published
for
github.com/minio/minio
(Go)
Mar 3, 2025
Spring Security Missing Authorization vulnerability
Moderate
CVE-2024-38810
was published
for
org.springframework.security:spring-security-core
(Maven)
Aug 20, 2024
Navidrome allows an authentication bypass in Subsonic API with non-existent username
Moderate
CVE-2025-27112
was published
for
github.com/navidrome/navidrome
(Go)
Feb 25, 2025
Apache DolphinScheduler's python gateway suffered from improper authentication
Moderate
CVE-2023-25601
was published
for
org.apache.dolphinscheduler:dolphinscheduler-api
(Maven)
Apr 20, 2023
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
actionpack Improper Authentication vulnerability
Moderate
CVE-2012-3424
was published
for
actionpack
(RubyGems)
Oct 24, 2017
matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content
Moderate
CVE-2024-36402
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Issue with whitespace in JWT roles in OpenSearch
Moderate
CVE-2023-23612
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Jan 24, 2023
ProTip!
Advisories are also available from the
GraphQL API