GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,386
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,480
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,053 advisories
Filter by severity
A flaw in Gliffy results in broken authentication through the reset functionality of the...
Moderate
Unreviewed
CVE-2024-5174
was published
Feb 24, 2025
An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate...
Moderate
Unreviewed
CVE-2024-54916
was published
Feb 12, 2025
Windows Remote Desktop Configuration Service Tampering Vulnerability
Moderate
Unreviewed
CVE-2025-21349
was published
Feb 11, 2025
An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to...
Moderate
Unreviewed
CVE-2024-52968
was published
Feb 11, 2025
Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an...
Moderate
Unreviewed
CVE-2025-1231
was published
Feb 11, 2025
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This...
Moderate
Unreviewed
CVE-2025-1104
was published
Feb 7, 2025
When multiple server blocks are configured to share the same IP address and port, an attacker can...
Moderate
Unreviewed
CVE-2025-23419
was published
Feb 5, 2025
If LDAP settings are accessed, authentication could be redirected to another server, potentially...
Moderate
Unreviewed
CVE-2024-12510
was published
Feb 3, 2025
API Security bypass through header manipulation
Moderate
Unreviewed
CVE-2024-55925
was published
Jan 23, 2025
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys,...
Moderate
Unreviewed
CVE-2024-42172
was published
Jan 11, 2025
A user with administrator privileges is able to retrieve authentication tokens
Moderate
Unreviewed
CVE-2024-9133
was published
Jan 11, 2025
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2024-13309
was published
Jan 9, 2025
Instruction authentication bypass vulnerability in the Findnetwork module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-56445
was published
Jan 8, 2025
Vulnerability of improper authentication in the ANS system service module
Impact: Successful...
Moderate
Unreviewed
CVE-2023-52955
was published
Jan 8, 2025
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan...
Moderate
Unreviewed
CVE-2024-13111
was published
Jan 2, 2025
CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the...
Moderate
Unreviewed
CVE-2024-10511
was published
Dec 11, 2024
An improper authentication vulnerability has been reported to affect several QNAP operating...
Moderate
Unreviewed
CVE-2024-48859
was published
Dec 6, 2024
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager...
Moderate
Unreviewed
CVE-2024-11671
was published
Nov 25, 2024
IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could
lead...
Moderate
Unreviewed
CVE-2022-33862
was published
Nov 25, 2024
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an...
Moderate
Unreviewed
CVE-2024-11209
was published
Nov 14, 2024
A vulnerability was found in pam_access due to the improper handling of tokens in access.conf,...
Moderate
Unreviewed
CVE-2024-10963
was published
Nov 7, 2024
A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2024-10620
was published
Nov 1, 2024
A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this...
Moderate
Unreviewed
CVE-2024-10173
was published
Oct 20, 2024
A vulnerability was found in Quay, which allows successful authentication even when a truncated...
Moderate
Unreviewed
CVE-2024-9683
was published
Oct 17, 2024
In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message...
Moderate
Unreviewed
CVE-2024-47127
was published
Sep 26, 2024
ProTip!
Advisories are also available from the
GraphQL API