GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,184 advisories
Filter by severity
A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0.
An...
High
Unreviewed
CVE-2024-11322
was published
Jan 15, 2025
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content...
Critical
Unreviewed
CVE-2024-12919
was published
Jan 14, 2025
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to...
Critical
Unreviewed
CVE-2025-0070
was published
Jan 14, 2025
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys,...
Moderate
Unreviewed
CVE-2024-42172
was published
Jan 11, 2025
A user with administrator privileges is able to retrieve authentication tokens
Moderate
Unreviewed
CVE-2024-9133
was published
Jan 11, 2025
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly...
Unknown
Unreviewed
CVE-2024-13309
was published
Jan 9, 2025
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote...
Critical
Unreviewed
CVE-2024-53704
was published
Jan 9, 2025
Vulnerability of improper authentication in the ANS system service module
Impact: Successful...
Moderate
Unreviewed
CVE-2023-52955
was published
Jan 8, 2025
Instruction authentication bypass vulnerability in the Findnetwork module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-56445
was published
Jan 8, 2025
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all...
Critical
Unreviewed
CVE-2024-12264
was published
Jan 7, 2025
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan...
Moderate
Unreviewed
CVE-2024-13111
was published
Jan 2, 2025
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
High
Unreviewed
CVE-2024-1609
was published
Dec 25, 2024
The AirVantage platform is vulnerable to an unauthorized attacker registering previously...
High
Unreviewed
CVE-2023-31279
was published
Dec 21, 2024
There is an insufficient authentication vulnerability in some Huawei smart phone. An...
Low
Unreviewed
CVE-2020-9250
was published
Dec 20, 2024
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
High
Unreviewed
CVE-2024-1610
was published
Dec 18, 2024
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all...
Critical
Unreviewed
CVE-2024-12287
was published
Dec 18, 2024
A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing...
Unknown
Unreviewed
CVE-2024-12603
was published
Dec 13, 2024
The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all...
Critical
Unreviewed
CVE-2024-11015
was published
Dec 12, 2024
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-10111
was published
Dec 12, 2024
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49076
was published
Dec 12, 2024
CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the...
Moderate
Unreviewed
CVE-2024-10511
was published
Dec 11, 2024
NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker...
High
Unreviewed
CVE-2024-0130
was published
Dec 6, 2024
An improper authentication vulnerability has been reported to affect several QNAP operating...
Moderate
Unreviewed
CVE-2024-48859
was published
Dec 6, 2024
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User...
High
Unreviewed
CVE-2024-11293
was published
Dec 4, 2024
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability....
Critical
Unreviewed
CVE-2024-11680
was published
Nov 26, 2024
ProTip!
Advisories are also available from the
GraphQL API