GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
359 advisories
Filter by severity
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense...
High
Unreviewed
CVE-2023-6221
was published
Feb 2, 2024
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote...
High
Unreviewed
CVE-2023-49115
was published
Feb 2, 2024
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication...
High
Unreviewed
CVE-2023-40545
was published
Feb 6, 2024
Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful...
High
Unreviewed
CVE-2022-48621
was published
Feb 18, 2024
RPyC's missing security check results in code execution when using numpy.array on the server-side.
High
CVE-2024-27758
was published
for
rpyc
(pip)
Mar 6, 2024
Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
High
CVE-2022-34321
was published
for
org.apache.pulsar:pulsar-proxy
(Maven)
Mar 12, 2024
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before...
High
Unreviewed
CVE-2024-2450
was published
Mar 15, 2024
Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service...
High
Unreviewed
CVE-2023-51571
was published
Apr 2, 2024
A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in...
High
Unreviewed
CVE-2024-3281
was published
Apr 9, 2024
Windows Update Stack Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26235
was published
Apr 9, 2024
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an...
High
Unreviewed
CVE-2023-4857
was published
Apr 15, 2024
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
High
Unreviewed
CVE-2024-21007
was published
Apr 17, 2024
The devices allow access to an unprotected endpoint that allows MPFS
file system binary image...
High
Unreviewed
CVE-2024-1491
was published
Apr 19, 2024
Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function...
High
Unreviewed
CVE-2023-38123
was published
May 3, 2024
D-Link DAP-1325 HNAP Missing Authentication Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2023-41187
was published
May 3, 2024
NETGEAR Orbi 760 SOAP API Authentication Bypass Vulnerability. This vulnerability allows network...
High
Unreviewed
CVE-2023-41183
was published
May 3, 2024
D-Link G416 httpd Missing Authentication for Critical Function Remote Code Execution...
High
Unreviewed
CVE-2023-50199
was published
May 3, 2024
Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure...
High
Unreviewed
CVE-2023-51587
was published
May 3, 2024
By design, the DHCP protocol does not authenticate messages, including for example the classless...
High
Unreviewed
CVE-2024-3661
was published
May 6, 2024
The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an...
High
Unreviewed
CVE-2024-2860
was published
May 8, 2024
An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access...
High
Unreviewed
CVE-2022-32503
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27942
was published
May 14, 2024
When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the...
High
Unreviewed
CVE-2023-5935
was published
May 15, 2024
Under certain circumstances communications between the ICU tool and an iSTAR Pro door controller...
High
Unreviewed
CVE-2024-32752
was published
Jun 6, 2024
Missing Authentication for Critical Function vulnerability in Aruphash Crafthemes Demo Import...
High
Unreviewed
CVE-2024-34800
was published
Jun 10, 2024
ProTip!
Advisories are also available from the
GraphQL API