GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
661
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
143 advisories
Filter by severity
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
Moderate
Unreviewed
CVE-2024-5249
was published
Jul 30, 2024
D-Link -
CWE-294: Authentication Bypass by Capture-replay
Critical
Unreviewed
CVE-2024-38438
was published
Jul 21, 2024
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
High
Unreviewed
CVE-2024-29850
was published
May 23, 2024
An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass...
Critical
Unreviewed
CVE-2023-47435
was published
Apr 19, 2024
Replay Attack
in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows...
Critical
Unreviewed
CVE-2024-4009
was published
Jun 5, 2024
Transmitted data is logged between the device and the backend service. An attacker could use...
Unknown
Unreviewed
CVE-2024-38284
was published
Jun 13, 2024
Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an...
High
Unreviewed
CVE-2022-25836
was published
Jul 6, 2023
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a replay...
Moderate
Unreviewed
CVE-2023-36857
was published
Oct 19, 2023
A Hyundai model (2017) - CWE-294: Authentication Bypass by Capture-replay.
Moderate
Unreviewed
CVE-2023-39373
was published
Sep 3, 2023
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation...
High
Unreviewed
CVE-2023-34625
was published
Jul 20, 2023
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause...
Critical
Unreviewed
CVE-2022-45789
was published
Jul 6, 2023
Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an...
High
Unreviewed
CVE-2022-25837
was published
Jul 6, 2023
Vulnerability of identity verification being bypassed in the storage module. Successful...
High
Unreviewed
CVE-2022-48507
was published
Jul 6, 2023
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric Corporation MELSEC...
Critical
Unreviewed
CVE-2023-2846
was published
Jun 30, 2023
An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via...
Moderate
Unreviewed
CVE-2023-34553
was published
Jun 22, 2023
SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which...
Critical
Unreviewed
CVE-2023-29158
was published
Jun 19, 2023
GL.iNET GL-AR750S-Ext firmware v3.215 inserts the admin authentication token into a GET request...
Moderate
Unreviewed
CVE-2023-33621
was published
Jun 13, 2023
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access...
High
Unreviewed
CVE-2023-31763
was published
May 24, 2023
Weak security in the transmitter of Blitzwolf BW-IS22 Smart Home Security Alarm v1.0 allows...
High
Unreviewed
CVE-2023-31761
was published
May 24, 2023
Weak security in the transmitter of Digoo DG-HAMB Smart Home Security System v1.0 allows...
High
Unreviewed
CVE-2023-31762
was published
May 24, 2023
Weak Security in the 433MHz keyfob of Kerui W18 Alarm System v1.0 allows attackers to gain full...
High
Unreviewed
CVE-2023-31759
was published
May 24, 2023
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful...
Moderate
Unreviewed
CVE-2020-14302
was published
May 24, 2022
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock...
Moderate
Unreviewed
CVE-2020-9438
was published
May 24, 2022
Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
Moderate
Unreviewed
CVE-2019-9158
was published
May 24, 2022
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and...
Moderate
Unreviewed
CVE-2019-5307
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API