GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
873 advisories
Filter by severity
Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08...
Critical
Unreviewed
CVE-2021-45511
was published
Dec 27, 2021
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin...
Critical
Unreviewed
CVE-2021-44526
was published
Dec 24, 2021
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality...
Critical
Unreviewed
CVE-2021-21952
was published
Dec 23, 2021
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible...
Critical
Unreviewed
CVE-2021-27451
was published
Dec 22, 2021
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2021-44675
was published
Dec 21, 2021
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass...
Critical
Unreviewed
CVE-2021-22057
was published
Dec 21, 2021
Authelia vulnerable to an authentication bypassed with malformed request URI on nginx
Critical
CVE-2021-32637
was published
for
github.com/authelia/authelia/v4
(Go)
Dec 20, 2021
The impacted products, when configured to use SSO, are affected by an improper authentication...
Critical
Unreviewed
CVE-2021-43935
was published
Dec 16, 2021
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated...
Critical
Unreviewed
CVE-2021-44524
was published
Dec 15, 2021
glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php.
Critical
Unreviewed
CVE-2021-44949
was published
Dec 15, 2021
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as...
Critical
Unreviewed
CVE-2021-4073
was published
Dec 15, 2021
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not...
Critical
Unreviewed
CVE-2021-44152
was published
Dec 14, 2021
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code...
Critical
Unreviewed
CVE-2021-44515
was published
Dec 13, 2021
ManageEngine's OpUtils 12.5.556 and prior allow access to a few audit directories without...
Critical
Unreviewed
CVE-2021-44514
was published
Dec 10, 2021
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable...
Critical
Unreviewed
CVE-2021-41716
was published
Dec 8, 2021
It was possible to bypass 2FA for LDAP users and access some specific pages with Basic...
Critical
Unreviewed
CVE-2021-39890
was published
Dec 7, 2021
The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be...
Critical
Unreviewed
CVE-2021-43931
was published
Dec 7, 2021
API token verification can be bypassed in NodeBB
Critical
CVE-2021-43786
was published
for
nodebb
(npm)
Nov 30, 2021
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and...
Critical
Unreviewed
CVE-2021-44077
was published
Nov 30, 2021
Improper Authentication in Apache ShenYu Admin
Critical
CVE-2021-37580
was published
for
org.apache.shenyu:shenyu-admin
(Maven)
Nov 17, 2021
Showdoc File Upload Vulnerability
Critical
CVE-2021-41745
was published
for
showdoc/showdoc
(Composer)
Oct 25, 2021
Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass
Critical
CVE-2021-41303
was published
for
org.apache.shiro:shiro-core
(Maven)
Sep 20, 2021
Improper Authenication in Pion DTLS
Critical
CVE-2019-20786
was published
for
github.com/pion/dtls
(Go)
Jun 29, 2021
XML Processing error in github.com/crewjam/saml
Critical
CVE-2020-27846
was published
for
github.com/crewjam/saml
(Go)
Jun 23, 2021
Authentication Bypass in tyk-identity-broker
Critical
CVE-2021-23365
was published
for
github.com/tyktechnologies/tyk-identity-broker
(Go)
Jun 23, 2021
ProTip!
Advisories are also available from the
GraphQL API