GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
885
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
239 advisories
Filter by severity
SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any...
Moderate
Unreviewed
CVE-2023-24526
was published
Mar 14, 2023
VMware Workspace ONE Content contains a passcode bypass vulnerability. A malicious actor, with...
Moderate
Unreviewed
CVE-2023-20857
was published
Feb 28, 2023
Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the...
Moderate
Unreviewed
CVE-2022-27891
was published
Feb 16, 2023
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one...
Moderate
Unreviewed
CVE-2022-3738
was published
Jan 19, 2023
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where...
Moderate
Unreviewed
CVE-2022-3188
was published
Dec 22, 2022
ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an...
Moderate
Unreviewed
CVE-2022-30515
was published
Nov 9, 2022
Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this...
Moderate
Unreviewed
CVE-2022-3675
was published
Nov 3, 2022
A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4...
Moderate
Unreviewed
CVE-2022-42473
was published
Nov 2, 2022
A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and...
Moderate
Unreviewed
CVE-2022-20830
was published
Oct 11, 2022
The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This...
Moderate
Unreviewed
CVE-2022-26394
was published
Sep 10, 2022
The Duplicator WordPress plugin before 1.4.7.1 does not authenticate or authorize visitors before...
Moderate
Unreviewed
CVE-2022-2552
was published
Aug 23, 2022
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS...
Moderate
Unreviewed
CVE-2021-36200
was published
Jul 23, 2022
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows...
Moderate
Unreviewed
CVE-2022-31260
was published
Jul 18, 2022
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service...
Moderate
Unreviewed
CVE-2022-23719
was published
Jul 1, 2022
The WPQA Builder WordPress plugin before 5.4 which is a companion to the Discy and Himer , lacks...
Moderate
Unreviewed
CVE-2022-1598
was published
Jun 9, 2022
The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY...
Moderate
Unreviewed
CVE-2022-22309
was published
May 25, 2022
** DISPUTED ** BIRD through 2.0.7 does not provide functionality for password authentication of...
Moderate
Unreviewed
CVE-2021-26928
was published
May 24, 2022
A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials....
Moderate
Unreviewed
CVE-2020-25634
was published
May 24, 2022
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote...
Moderate
Unreviewed
CVE-2019-8449
was published
May 24, 2022
Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access,...
Moderate
Unreviewed
CVE-2021-33259
was published
May 24, 2022
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the...
Moderate
Unreviewed
CVE-2021-41568
was published
May 24, 2022
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers...
Moderate
Unreviewed
CVE-2021-41976
was published
May 24, 2022
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker...
Moderate
Unreviewed
CVE-2021-39879
was published
May 24, 2022
A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing...
Moderate
Unreviewed
CVE-2019-10941
was published
May 24, 2022
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR...
Moderate
Unreviewed
CVE-2021-27668
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API