GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
257 advisories
Filter by severity
A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe...
Moderate
Unreviewed
CVE-2024-30391
was published
Apr 12, 2024
A potential vulnerability was reported in the BIOS update tool driver for some Desktop, Smart...
Moderate
Unreviewed
CVE-2023-25493
was published
Apr 5, 2024
** DISPUTED ** A Missing Authentication for Critical Function issue affecting the HTTP service...
Moderate
Unreviewed
CVE-2023-6949
was published
Apr 2, 2024
Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue...
Moderate
Unreviewed
CVE-2022-38057
was published
Mar 25, 2024
Improper authentication vulnerability in exists in multiple printers and scanners which implement...
Moderate
Unreviewed
CVE-2024-21824
was published
Mar 18, 2024
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as...
Moderate
Unreviewed
CVE-2024-2076
was published
Mar 1, 2024
Internet passwords stored in Person documents in the Domino® Directory created using the "Add...
Moderate
Unreviewed
CVE-2023-37495
was published
Feb 29, 2024
EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing...
Moderate
Unreviewed
CVE-2024-26263
was published
Feb 15, 2024
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for...
Moderate
Unreviewed
CVE-2024-22449
was published
Feb 1, 2024
Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records
Moderate
CVE-2020-15136
was published
for
go.etcd.io/etcd
(Go)
Jan 31, 2024
A missing authentication check in the WebSocket channel used for the Check Point IoT integration...
Moderate
Unreviewed
CVE-2023-5253
was published
Jan 15, 2024
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions...
Moderate
Unreviewed
CVE-2023-51062
was published
Jan 13, 2024
NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication...
Moderate
Unreviewed
CVE-2023-31033
was published
Jan 12, 2024
Microsoft Bluetooth Driver Spoofing Vulnerability
Moderate
Unreviewed
CVE-2024-21306
was published
Jan 9, 2024
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an...
Moderate
Unreviewed
CVE-2023-6368
was published
Dec 14, 2023
The FACSChorus workstation operating system does not restrict what devices can interact with its...
Moderate
Unreviewed
CVE-2023-29060
was published
Nov 28, 2023
There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to...
Moderate
Unreviewed
CVE-2023-29061
was published
Nov 28, 2023
Lack of authentication vulnerability. An unauthenticated local user is able to see through the...
Moderate
Unreviewed
CVE-2023-3104
was published
Nov 22, 2023
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). The PUD Manager of...
Moderate
Unreviewed
CVE-2023-46096
was published
Nov 14, 2023
Missing Authentication in Apache Software Foundation Apache OFBiz when using the Solr plugin....
Moderate
Unreviewed
CVE-2023-46819
was published
Nov 10, 2023
An authentication issue was addressed with improved state management. This issue is fixed in...
Moderate
Unreviewed
CVE-2023-42845
was published
Oct 25, 2023
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring...
Moderate
Unreviewed
CVE-2023-39231
was published
Oct 25, 2023
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3...
Moderate
Unreviewed
CVE-2023-27261
was published
Oct 25, 2023
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and...
Moderate
Unreviewed
CVE-2023-27256
was published
Oct 25, 2023
Missing authentication in the DeleteStaff method in IDAttend’s IDWeb application 3.1.013 allows...
Moderate
Unreviewed
CVE-2023-26579
was published
Oct 25, 2023
ProTip!
Advisories are also available from the
GraphQL API