GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
885
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
330 advisories
Filter by severity
An unauthenticated remote attacker can modify configurations to perform a remote code execution...
Critical
Unreviewed
CVE-2024-25995
was published
Mar 12, 2024
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
Critical
Unreviewed
CVE-2024-10284
was published
Nov 9, 2024
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business...
Critical
Unreviewed
CVE-2022-26143
was published
Mar 11, 2022
Undisclosed requests may bypass configuration utility authentication, allowing an attacker...
Critical
Unreviewed
CVE-2023-46747
was published
Oct 26, 2023
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability...
Critical
Unreviewed
CVE-2023-1096
was published
May 12, 2023
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to,...
Critical
Unreviewed
CVE-2024-12857
was published
Jan 22, 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
Critical
Unreviewed
CVE-2025-21535
was published
Jan 21, 2025
Even if the authentication fails for local service authentication, the requested command could...
Critical
Unreviewed
CVE-2022-46732
was published
Jan 18, 2023
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote...
Critical
Unreviewed
CVE-2024-11639
was published
Dec 10, 2024
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing...
Critical
Unreviewed
CVE-2025-0456
was published
Jan 16, 2025
A firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8...
Critical
Unreviewed
CVE-2024-39273
was published
Jan 14, 2025
A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8...
Critical
Unreviewed
CVE-2024-39608
was published
Jan 14, 2025
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication...
Critical
Unreviewed
CVE-2023-33553
was published
Jun 7, 2023
Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this...
Critical
Unreviewed
CVE-2023-30762
was published
Jun 13, 2023
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a...
Critical
Unreviewed
CVE-2024-54983
was published
Dec 20, 2024
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass...
Critical
Unreviewed
CVE-2024-54982
was published
Dec 20, 2024
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted...
Critical
Unreviewed
CVE-2024-54984
was published
Dec 20, 2024
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP...
Critical
Unreviewed
CVE-2024-12106
was published
Dec 31, 2024
A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A...
Critical
Unreviewed
CVE-2024-21855
was published
Dec 20, 2024
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This...
Critical
Unreviewed
CVE-2024-12371
was published
Dec 18, 2024
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive,...
Critical
Unreviewed
CVE-2022-23227
was published
Jan 15, 2022
Missing Authentication for Critical Function vulnerability in OpenText™ AccuRev for LDAP...
Critical
Unreviewed
CVE-2019-17082
was published
Nov 26, 2024
Authentication Bypass
vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops...
Critical
Unreviewed
CVE-2024-10205
was published
Dec 17, 2024
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server...
Critical
Unreviewed
CVE-2023-42793
was published
Sep 19, 2023
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated...
Critical
Unreviewed
CVE-2024-0012
was published
Nov 18, 2024
ProTip!
Advisories are also available from the
GraphQL API