GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,057
Maven
5,000+
npm
3,742
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
318 advisories
Filter by severity
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a...
Critical
Unreviewed
CVE-2024-54983
was published
Dec 20, 2024
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted...
Critical
Unreviewed
CVE-2024-54984
was published
Dec 20, 2024
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass...
Critical
Unreviewed
CVE-2024-54982
was published
Dec 20, 2024
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP...
Critical
Unreviewed
CVE-2024-12106
was published
Dec 31, 2024
A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A...
Critical
Unreviewed
CVE-2024-21855
was published
Dec 20, 2024
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This...
Critical
Unreviewed
CVE-2024-12371
was published
Dec 18, 2024
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive,...
Critical
Unreviewed
CVE-2022-23227
was published
Jan 15, 2022
Missing Authentication for Critical Function vulnerability in OpenText™ AccuRev for LDAP...
Critical
Unreviewed
CVE-2019-17082
was published
Nov 26, 2024
Authentication Bypass
vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops...
Critical
Unreviewed
CVE-2024-10205
was published
Dec 17, 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server...
Critical
Unreviewed
CVE-2023-42793
was published
Sep 19, 2023
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated...
Critical
Unreviewed
CVE-2024-0012
was published
Nov 18, 2024
Certain modes of in-vehicle routers from Billion Electric have a Missing Authentication...
Critical
Unreviewed
CVE-2024-11980
was published
Nov 29, 2024
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an...
Critical
Unreviewed
CVE-2024-5910
was published
Jul 10, 2024
STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and...
Critical
Unreviewed
CVE-2023-35830
was published
Jun 29, 2023
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access...
Critical
Unreviewed
CVE-2024-40404
was published
Nov 14, 2024
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An...
Critical
Unreviewed
CVE-2023-28461
was published
Mar 16, 2023
The administrative interface listens by default on all interfaces on a TCP port and does not...
Critical
Unreviewed
CVE-2024-47138
was published
Nov 23, 2024
A missing authentication for critical function vulnerability has been reported to affect Notes...
Critical
Unreviewed
CVE-2024-38643
was published
Nov 22, 2024
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to...
Critical
Unreviewed
CVE-2024-10924
was published
Nov 15, 2024
The software tools used by service personnel to test & calibrate the ventilator do not support...
Critical
Unreviewed
CVE-2024-48966
was published
Nov 15, 2024
Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation...
Critical
Unreviewed
CVE-2023-4699
was published
Nov 6, 2023
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows...
Critical
Unreviewed
CVE-2024-51567
was published
Oct 30, 2024
Improper access control in PAM vault permissions in Devolutions Server 2024.1.6 and earlier...
Critical
Unreviewed
CVE-2024-2921
was published
Mar 26, 2024
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an...
Critical
Unreviewed
CVE-2024-47406
was published
Oct 25, 2024
In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page)...
Critical
Unreviewed
CVE-2022-31266
was published
Jun 30, 2022
ProTip!
Advisories are also available from the
GraphQL API