GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
441 advisories
Filter by severity
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2025-8861
was published
Aug 29, 2025
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows...
Critical
Unreviewed
CVE-2025-30039
was published
Aug 27, 2025
The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat...
Critical
Unreviewed
CVE-2025-30041
was published
Aug 27, 2025
The vulnerability allows unauthenticated users to download a file containing session ID data by...
Critical
Unreviewed
CVE-2025-30040
was published
Aug 27, 2025
Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were...
Critical
Unreviewed
CVE-2025-25736
was published
Aug 26, 2025
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control...
Critical
Unreviewed
CVE-2025-53118
was published
Aug 26, 2025
WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2025-9254
was published
Aug 22, 2025
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro...
Critical
Unreviewed
CVE-2025-27214
was published
Aug 21, 2025
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution...
Critical
Unreviewed
CVE-2025-8610
was published
Aug 20, 2025
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution...
Critical
Unreviewed
CVE-2025-8611
was published
Aug 20, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator...
Critical
Unreviewed
CVE-2025-8995
was published
Aug 15, 2025
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control...
Critical
Unreviewed
CVE-2025-43983
was published
Aug 14, 2025
Flowise OS command remote code execution
Critical
CVE-2025-8943
was published
for
flowise
(npm)
Aug 14, 2025
Burk Technology ARC Solo's password change mechanism can be utilized without proper ...
Critical
Unreviewed
CVE-2025-5095
was published
Aug 8, 2025
By default, the Packet Power Monitoring and Control Web Interface do not
enforce authentication...
Critical
Unreviewed
CVE-2025-8284
was published
Aug 8, 2025
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System...
Critical
Unreviewed
CVE-2014-125113
was published
Aug 5, 2025
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote...
Critical
Unreviewed
CVE-2012-10030
was published
Aug 5, 2025
Güralp FMUS series seismic monitoring devices expose an unauthenticated Telnet-based command line...
Critical
Unreviewed
CVE-2025-8286
was published
Jul 31, 2025
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that...
Critical
Unreviewed
CVE-2014-125126
was published
Jul 31, 2025
A Missing Authentication for Critical Function vulnerability in SUSE Manager allows anyone with...
Critical
Unreviewed
CVE-2025-46811
was published
Jul 30, 2025
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without...
Critical
Unreviewed
CVE-2025-30135
was published
Jul 25, 2025
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to...
Critical
Unreviewed
CVE-2014-125116
was published
Jul 25, 2025
The embedded web server on the thermostat listed version ranges contain a vulnerability that...
Critical
Unreviewed
CVE-2025-6260
was published
Jul 24, 2025
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station...
Critical
Unreviewed
CVE-2025-34121
was published
Jul 16, 2025
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior...
Critical
Unreviewed
CVE-2025-34104
was published
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API