GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,470
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
293 advisories
Filter by severity
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
Critical
Unreviewed
CVE-2023-32220
was published
Jun 12, 2023
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members...
Critical
Unreviewed
CVE-2024-1741
was published
Apr 10, 2024
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue...
Critical
Unreviewed
CVE-2024-13278
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue...
Critical
Unreviewed
CVE-2024-13277
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows...
Critical
Unreviewed
CVE-2024-13253
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows...
Critical
Unreviewed
CVE-2024-13258
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue...
Critical
Unreviewed
CVE-2024-13281
was published
Jan 9, 2025
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360...
Critical
Unreviewed
CVE-2022-29081
was published
Apr 29, 2022
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business...
Critical
Unreviewed
CVE-2022-26143
was published
Mar 11, 2022
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a...
Critical
Unreviewed
CVE-2023-23304
was published
May 23, 2023
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products...
Critical
Unreviewed
CVE-2023-27388
was published
May 23, 2023
SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on...
Critical
Unreviewed
CVE-2024-47857
was published
Jan 31, 2025
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys...
Critical
Unreviewed
CVE-2024-57432
was published
Jan 31, 2025
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass...
Critical
Unreviewed
CVE-2024-53553
was published
Jan 17, 2025
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile...
Critical
Unreviewed
CVE-2025-21556
was published
Jan 21, 2025
The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS...
Critical
Unreviewed
CVE-2024-54512
was published
Jan 28, 2025
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this...
Critical
Unreviewed
CVE-2020-2506
was published
May 24, 2022
Apache Submarine Server Core Incorrect Authorization vulnerability
Critical
CVE-2024-36265
was published
for
apache-submarine
(Maven)
Jun 12, 2024
ProTip!
Advisories are also available from the
GraphQL API