GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
117 advisories
Filter by severity
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase...
Critical
Unreviewed
CVE-2023-27746
was published
Apr 13, 2023
AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force...
Critical
Unreviewed
CVE-2019-12941
was published
May 24, 2022
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection...
Critical
Unreviewed
CVE-2019-17240
was published
May 24, 2022
An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05...
Critical
Unreviewed
CVE-2019-17215
was published
May 24, 2022
Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive...
Critical
Unreviewed
CVE-2019-3766
was published
May 24, 2022
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1)....
Critical
Unreviewed
CVE-2019-13918
was published
May 24, 2022
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for...
Critical
Unreviewed
CVE-2013-4441
was published
May 5, 2022
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that...
Critical
Unreviewed
CVE-2024-2051
was published
Mar 18, 2024
OpenCart v4.0.2.2 is vulnerable to Brute Force Attack.
Critical
Unreviewed
CVE-2023-40834
was published
Sep 12, 2023
A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000,...
Critical
Unreviewed
CVE-2021-41435
was published
Nov 20, 2021
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts,...
Critical
Unreviewed
CVE-2023-33759
was published
Jan 25, 2024
IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow...
Critical
Unreviewed
CVE-2024-22317
was published
Jan 18, 2024
Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows...
Critical
Unreviewed
CVE-2023-27172
was published
Dec 20, 2023
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts,...
Critical
Unreviewed
CVE-2023-6272
was published
Dec 18, 2023
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and...
Critical
Unreviewed
CVE-2023-49443
was published
Dec 8, 2023
EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess...
Critical
Unreviewed
CVE-2023-6928
was published
Dec 20, 2023
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web...
Critical
Unreviewed
CVE-2023-35039
was published
Dec 7, 2023
kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the...
Critical
Unreviewed
CVE-2023-48028
was published
Nov 18, 2023
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined...
Critical
Unreviewed
CVE-2023-0574
was published
Feb 9, 2023
The cookie session ID is of insufficient length and can be exploited by
brute force, which may...
Critical
Unreviewed
CVE-2023-42769
was published
Oct 26, 2023
Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily...
Critical
Unreviewed
CVE-2023-5754
was published
Oct 26, 2023
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake...
Critical
Unreviewed
CVE-2023-2675
was published
Nov 13, 2023
AzuraCast missing brute force prevention
Critical
CVE-2023-2531
was published
for
azuracast/azuracast
(Composer)
May 5, 2023
Froxlor vulnerable to Improper Restriction of Excessive Authentication Attempts
Critical
CVE-2023-3173
was published
for
froxlor/froxlor
(Composer)
Jun 9, 2023
User login brute force protection functionality bypass
Critical
Unreviewed
CVE-2022-27516
was published
Nov 9, 2022
ProTip!
Advisories are also available from the
GraphQL API