GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
243 advisories
Filter by severity
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys...
Critical
Unreviewed
CVE-2024-57432
was published
Jan 31, 2025
SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on...
Critical
Unreviewed
CVE-2024-47857
was published
Jan 31, 2025
The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS...
Critical
Unreviewed
CVE-2024-54512
was published
Jan 28, 2025
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile...
Critical
Unreviewed
CVE-2025-21556
was published
Jan 21, 2025
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass...
Critical
Unreviewed
CVE-2024-53553
was published
Jan 17, 2025
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue...
Critical
Unreviewed
CVE-2024-13278
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue...
Critical
Unreviewed
CVE-2024-13277
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue...
Critical
Unreviewed
CVE-2024-13281
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows...
Critical
Unreviewed
CVE-2024-13253
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows...
Critical
Unreviewed
CVE-2024-13258
was published
Jan 9, 2025
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android...
Critical
Unreviewed
CVE-2023-4617
was published
Dec 19, 2024
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf...
Critical
Unreviewed
CVE-2024-54662
was published
Dec 17, 2024
Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value...
Critical
Unreviewed
CVE-2024-52732
was published
Dec 2, 2024
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability....
Critical
Unreviewed
CVE-2024-11680
was published
Nov 26, 2024
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS...
Critical
Unreviewed
CVE-2024-31695
was published
Nov 15, 2024
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows...
Critical
Unreviewed
CVE-2024-3379
was published
Nov 14, 2024
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of...
Critical
Unreviewed
CVE-2024-48176
was published
Nov 6, 2024
A permissions issue was addressed by removing vulnerable code and adding additional checks. This...
Critical
Unreviewed
CVE-2024-44217
was published
Oct 29, 2024
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController...
Critical
Unreviewed
CVE-2024-48237
was published
Oct 26, 2024
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control....
Critical
Unreviewed
CVE-2024-41617
was published
Oct 25, 2024
The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding...
Critical
Unreviewed
CVE-2024-48548
was published
Oct 24, 2024
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0...
Critical
Unreviewed
CVE-2024-38002
was published
Oct 22, 2024
An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker...
Critical
Unreviewed
CVE-2024-48786
was published
Oct 11, 2024
An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker...
Critical
Unreviewed
CVE-2024-48784
was published
Oct 11, 2024
An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive...
Critical
Unreviewed
CVE-2024-48772
was published
Oct 11, 2024
ProTip!
Advisories are also available from the
GraphQL API