GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,159 advisories
Filter by severity
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5718
was published
Nov 22, 2024
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5721
was published
Nov 22, 2024
A missing authentication for critical function vulnerability has been reported to affect Notes...
Critical
Unreviewed
CVE-2024-38643
was published
Nov 22, 2024
Missing Authentication for Critical Function vulnerability in deco.Agency de:branding allows...
High
Unreviewed
CVE-2024-52438
was published
Nov 20, 2024
Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System...
High
Unreviewed
CVE-2024-52437
was published
Nov 20, 2024
Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware...
Moderate
Unreviewed
CVE-2024-47865
was published
Nov 20, 2024
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated...
Critical
Unreviewed
CVE-2024-0012
was published
Nov 18, 2024
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a...
High
Unreviewed
CVE-2024-41969
was published
Nov 18, 2024
A low privileged remote attacker may modify the boot mode configuration setup of the device,...
High
Unreviewed
CVE-2024-41967
was published
Nov 18, 2024
A low privileged remote attacker may modify the docker settings setup of the device, leading to a...
Moderate
Unreviewed
CVE-2024-41968
was published
Nov 18, 2024
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to...
Critical
Unreviewed
CVE-2024-10924
was published
Nov 15, 2024
Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without...
Moderate
Unreviewed
CVE-2024-39707
was published
Nov 15, 2024
The software tools used by service personnel to test & calibrate the ventilator do not support...
Critical
Unreviewed
CVE-2024-48966
was published
Nov 15, 2024
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access...
Critical
Unreviewed
CVE-2024-40404
was published
Nov 14, 2024
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access...
High
Unreviewed
CVE-2024-40408
was published
Nov 14, 2024
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows...
High
Unreviewed
CVE-2024-40405
was published
Nov 14, 2024
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version...
High
Unreviewed
CVE-2024-47574
was published
Nov 13, 2024
A vulnerability in Brocade Fabric OS versions before 9.2.2 could allow man-in-the-middle...
High
Unreviewed
CVE-2024-7516
was published
Nov 12, 2024
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4...
Moderate
Unreviewed
CVE-2024-26011
was published
Nov 12, 2024
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
Critical
Unreviewed
CVE-2024-10284
was published
Nov 9, 2024
An unauthenticated attacker with access to the local network of the
medical office can query an...
High
Unreviewed
CVE-2024-50589
was published
Nov 8, 2024
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting...
High
Unreviewed
CVE-2024-48953
was published
Nov 7, 2024
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup...
High
Unreviewed
CVE-2024-48950
was published
Nov 7, 2024
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate...
Moderate
Unreviewed
CVE-2024-48952
was published
Nov 7, 2024
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue...
Moderate
Unreviewed
CVE-2024-51362
was published
Nov 5, 2024
ProTip!
Advisories are also available from the
GraphQL API