GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,770
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
265 advisories
Filter by severity
Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without...
Moderate
Unreviewed
CVE-2024-39707
was published
Nov 15, 2024
A low privileged remote attacker may modify the docker settings setup of the device, leading to a...
Moderate
Unreviewed
CVE-2024-41968
was published
Nov 18, 2024
Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware...
Moderate
Unreviewed
CVE-2024-47865
was published
Nov 20, 2024
Improper control of framework service permissions with possibility of some sensitive device...
Moderate
Unreviewed
CVE-2020-12491
was published
Nov 25, 2024
Admin authentication can be bypassed with some specific invalid credentials, which allows logging...
Moderate
Unreviewed
CVE-2024-33616
was published
Nov 26, 2024
Synapse's unauthenticated writes to the media repository allow planting of problematic content
Moderate
CVE-2024-37303
was published
for
matrix-synapse
(pip)
Dec 3, 2024
When using special mode to connect to enterprise wifi, certain options are not properly...
Moderate
Unreviewed
CVE-2020-12484
was published
Dec 17, 2024
The wifi module exposes the interface and has improper permission control, leaking sensitive...
Moderate
Unreviewed
CVE-2021-26278
was published
Dec 17, 2024
Sensitive information disclosure due to missing authentication. The following products are...
Moderate
Unreviewed
CVE-2024-55538
was published
Jan 2, 2025
The health module has insufficient restrictions on loading URLs, which may lead to some...
Moderate
Unreviewed
CVE-2024-13173
was published
Jan 8, 2025
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some...
Moderate
Unreviewed
CVE-2024-13186
was published
Jan 8, 2025
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some...
Moderate
Unreviewed
CVE-2024-13185
was published
Jan 8, 2025
An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000...
Moderate
Unreviewed
CVE-2024-39773
was published
Jan 14, 2025
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication...
Moderate
Unreviewed
CVE-2025-24456
was published
Jan 21, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-21559
was published
Jan 21, 2025
ProTip!
Advisories are also available from the
GraphQL API