GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
410 advisories
Filter by severity
A vulnerability was identified in LogicalDOC Community Edition up to 9.2.1. This vulnerability...
Moderate
Unreviewed
CVE-2025-12547
was published
Oct 31, 2025
Nagios Fusion versions prior to 2024R2.1 contain a brute-force bypass in the Two-Factor...
Critical
Unreviewed
CVE-2025-34249
was published
Oct 31, 2025
Liferay Portal vulnerable to password enumeration
Moderate
CVE-2025-62257
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 30, 2025
Drupal Access code allows Brute Force Attempts
Moderate
CVE-2025-10928
was published
for
drupal/access_code
(Composer)
Oct 30, 2025
Zitadel allows brute-forcing authentication factors
High
CVE-2025-64102
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
A security vulnerability has been detected in VirtFusion up to 6.0.2. This vulnerability affects...
Moderate
Unreviewed
CVE-2025-12310
was published
Oct 27, 2025
Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless...
Low
Unreviewed
CVE-2025-26862
was published
Oct 27, 2025
Moodle vulnerable to brute-force password guesses
High
CVE-2025-62399
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8...
Moderate
Unreviewed
CVE-2025-56224
was published
Oct 20, 2025
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass...
Critical
Unreviewed
CVE-2025-56221
was published
Oct 17, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages...
Moderate
Unreviewed
CVE-2025-9551
was published
Oct 11, 2025
A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown...
Moderate
Unreviewed
CVE-2025-11441
was published
Oct 8, 2025
The application does not implement sufficient measures to prevent multiple failed authentication...
Moderate
Unreviewed
CVE-2025-58587
was published
Oct 6, 2025
In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via...
High
Unreviewed
CVE-2025-8679
was published
Oct 1, 2025
PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count...
Moderate
Unreviewed
CVE-2025-8118
was published
Sep 30, 2025
IBM Sterling Connect:Express for Microsoft Windows 3.1.0.0 through 3.1.0.22 uses an inadequate...
Moderate
Unreviewed
CVE-2025-36064
was published
Sep 22, 2025
A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api...
Moderate
Unreviewed
CVE-2025-10761
was published
Sep 22, 2025
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-10658
was published
Sep 22, 2025
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with...
High
Unreviewed
CVE-2025-35041
was published
Sep 22, 2025
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in...
Moderate
Unreviewed
CVE-2025-54860
was published
Sep 19, 2025
It is possible to bypass the clipping level of authentication attempts in SolaX Cloud through the...
Moderate
Unreviewed
CVE-2025-36758
was published
Sep 10, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides has a Lack of Brute-Force Protections on Authentication Endpoints
Low
CVE-2025-57815
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano...
High
Unreviewed
CVE-2025-2411
was published
Sep 4, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat...
High
Unreviewed
CVE-2025-2417
was published
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API