GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
450 advisories
Filter by severity
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to...
High
Unreviewed
CVE-2024-48768
was published
Oct 11, 2024
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2024-48773
was published
Oct 11, 2024
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain...
High
Unreviewed
CVE-2024-48775
was published
Oct 11, 2024
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information...
High
Unreviewed
CVE-2024-48776
was published
Oct 11, 2024
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions...
High
Unreviewed
CVE-2024-9522
was published
Oct 10, 2024
Missing authentication for critical function in Visual Studio Code extension for Arduino allows...
High
Unreviewed
CVE-2024-43488
was published
Oct 8, 2024
Missing Authentication - User & System Configuration
High
Unreviewed
CVE-2024-47555
was published
Oct 7, 2024
Advantech ADAM-5630
has built-in commands that can be executed without authenticating the
user....
High
Unreviewed
CVE-2024-39364
was published
Sep 27, 2024
The goTenna Pro series allows unauthenticated attackers to remotely update the local public keys...
High
Unreviewed
CVE-2024-47130
was published
Sep 26, 2024
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up...
High
Unreviewed
CVE-2024-7781
was published
Sep 26, 2024
Duplicate Advisory: Mautic has insufficient authentication in upgrade flow
High
GHSA-5hc5-fxr9-5frc
was published
for
mautic/core
(Composer)
Sep 19, 2024
•
withdrawn
Withdrawn Advisory: Lunary Improper Authentication vulnerability
High
CVE-2024-6582
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP...
High
Unreviewed
CVE-2024-8751
was published
Sep 13, 2024
An authentication bypass weakness in the message broker service of Ivanti Workspace Control...
High
Unreviewed
CVE-2024-8012
was published
Sep 10, 2024
Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and...
High
Unreviewed
CVE-2024-39300
was published
Aug 30, 2024
Chisel's AUTH environment variable not respected in server entrypoint
High
CVE-2024-43798
was published
for
github.com/jpillora/chisel
(Go)
Aug 27, 2024
The product exposes a service that is intended for local only to
all network interfaces without...
High
Unreviewed
CVE-2024-7940
was published
Aug 27, 2024
Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects...
High
Unreviewed
CVE-2024-7125
was published
Aug 27, 2024
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2024-7628
was published
Aug 15, 2024
A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00...
High
Unreviewed
CVE-2024-35124
was published
Aug 13, 2024
Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass...
High
Unreviewed
CVE-2024-7007
was published
Jul 25, 2024
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5...
High
Unreviewed
CVE-2024-39601
was published
Jul 22, 2024
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in...
High
Unreviewed
CVE-2024-6635
was published
Jul 20, 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
High
Unreviewed
CVE-2024-21183
was published
Jul 17, 2024
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL...
High
Unreviewed
CVE-2024-21146
was published
Jul 17, 2024
ProTip!
Advisories are also available from the
GraphQL API