GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,705
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
155 advisories
Filter by severity
Improper Authentication in OpenSAML
Moderate
CVE-2011-1411
was published
for
org.opensaml:opensaml
(Maven)
May 17, 2022
OpenStack Keystone Improper Authentication vulnerability
Moderate
CVE-2013-1865
was published
for
keystone
(pip)
May 17, 2022
TYPO3 Improper Session Invalidation
Moderate
CVE-2014-3944
was published
for
typo3/cms
(Composer)
May 17, 2022
OpenStack Neutron Improper Authentication vulnerability
Moderate
CVE-2014-0056
was published
for
neutron
(pip)
May 17, 2022
Jenkins does not invalidate the API token when a user is deleted
Moderate
CVE-2014-2062
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins session fixation vulnerability
Moderate
CVE-2014-2066
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Improper Authentication in Apache ActiveMQ
Moderate
CVE-2013-3060
was published
for
org.apache.activemq:activemq-client
(Maven)
May 17, 2022
Salt Insecure configuration of PAM external authentication service
Moderate
CVE-2016-3176
was published
for
salt
(pip)
May 17, 2022
Chameleon in Plone allows Authentication Bypass
Moderate
CVE-2016-4043
was published
for
Plone
(pip)
May 17, 2022
Apache Hadoop allows impersonation of arbitrary cluster user accounts
Moderate
CVE-2012-1574
was published
for
org.apache.hadoop:hadoop-main
(Maven)
May 17, 2022
Improper Authentication in Apache Hadoop
Moderate
CVE-2014-0229
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
Apache QPID Allows Remote Authentication Bypass
Moderate
CVE-2012-3467
was published
for
org.apache.qpid:qpid-parent
(Maven)
May 17, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2012-5886
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
May 17, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2012-5887
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
Moderate
CVE-2013-2059
was published
for
keystone
(pip)
May 17, 2022
Authentication Bypass in Apache Tomcat
Moderate
CVE-2012-3546
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
Zend Access Restriction Bypass
Moderate
CVE-2014-8088
was published
for
zendframework/zendframework
(Composer)
May 17, 2022
Django Middleware Enables Session Hijacking
Moderate
CVE-2014-0482
was published
for
Django
(pip)
May 14, 2022
OpenStack Keystone Token authorization for a user in a disabled tenant is allowed
Moderate
CVE-2012-4457
was published
for
Keystone
(pip)
May 14, 2022
Improper Authentication in Hibernate Validator
Moderate
CVE-2014-3558
was published
for
org.hibernate:hibernate-validator
(Maven)
May 14, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2011-5062
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2011-5063
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Authentication in Apache Tomcat
Moderate
CVE-2013-2067
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Authentication in Jenkins
Moderate
CVE-2018-1999045
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Apache OpenMeetings may allow authenticated attacker to deny service for privileged users
Moderate
CVE-2018-1286
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API