GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
287 advisories
Filter by severity
A missing delay in popup notifications could have made it possible for an attacker to trick a...
High
Unreviewed
CVE-2023-32207
was published
Jun 2, 2023
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local...
Moderate
Unreviewed
CVE-2023-6044
was published
Jan 19, 2024
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2023-20245
was published
Nov 1, 2023
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2023-20256
was published
Nov 1, 2023
Multiple Cisco products are affected by a vulnerability in Snort access control policies that...
Moderate
Unreviewed
CVE-2023-20246
was published
Nov 1, 2023
A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and...
Critical
Unreviewed
CVE-2023-51350
was published
Jan 12, 2024
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful...
High
Unreviewed
CVE-2023-44117
was published
Jan 16, 2024
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful...
High
Unreviewed
CVE-2023-4566
was published
Jan 16, 2024
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and...
Moderate
Unreviewed
CVE-2024-0454
was published
Jan 12, 2024
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2....
Moderate
Unreviewed
CVE-2021-32076
was published
May 24, 2022
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows...
Moderate
Unreviewed
CVE-2023-7169
was published
Feb 8, 2024
An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via...
High
Unreviewed
CVE-2024-22519
was published
Feb 7, 2024
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a...
Moderate
Unreviewed
CVE-2023-4001
was published
Jan 15, 2024
Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to...
High
Unreviewed
CVE-2022-30319
was published
Jul 29, 2022
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
Moderate
CVE-2024-21494
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820...
High
Unreviewed
CVE-2009-1048
was published
May 2, 2022
An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones...
High
Unreviewed
CVE-2024-22520
was published
Feb 7, 2024
Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS...
High
Unreviewed
CVE-2024-22457
was published
Mar 1, 2024
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in...
Moderate
Unreviewed
CVE-2024-28228
was published
Mar 7, 2024
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a
allows remote...
Critical
Unreviewed
CVE-2023-31424
was published
Aug 31, 2023
** UNSUPPPORTED WHEN ASSIGNED **
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an...
Critical
Unreviewed
CVE-2023-3243
was published
Jun 28, 2023
in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification...
High
Unreviewed
CVE-2024-22092
was published
Apr 2, 2024
Cache Poisoning issue exists in DNS Response Rate Limiting.
Moderate
Unreviewed
CVE-2013-5661
was published
May 5, 2022
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential...
Moderate
Unreviewed
CVE-2019-18659
was published
May 24, 2022
Legacy pairing and secure-connections pairing authentication in Bluetooth® BR/EDR Core...
Moderate
Unreviewed
CVE-2020-10135
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API