GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,245 advisories
Filter by severity
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before...
High
Unreviewed
CVE-2024-2450
was published
Mar 15, 2024
Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
High
CVE-2022-34321
was published
for
org.apache.pulsar:pulsar-proxy
(Maven)
Mar 12, 2024
An unauthenticated remote attacker can modify configurations to perform a remote code execution...
Critical
Unreviewed
CVE-2024-25995
was published
Mar 12, 2024
RPyC's missing security check results in code execution when using numpy.array on the server-side.
High
CVE-2024-27758
was published
for
rpyc
(pip)
Mar 6, 2024
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as...
Moderate
Unreviewed
CVE-2024-2076
was published
Mar 1, 2024
Internet passwords stored in Person documents in the Domino® Directory created using the "Add...
Moderate
Unreviewed
CVE-2023-37495
was published
Feb 29, 2024
Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful...
High
Unreviewed
CVE-2022-48621
was published
Feb 18, 2024
EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing...
Moderate
Unreviewed
CVE-2024-26263
was published
Feb 15, 2024
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication...
High
Unreviewed
CVE-2023-40545
was published
Feb 6, 2024
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
Critical
Unreviewed
CVE-2024-23917
was published
Feb 6, 2024
The MachineSense application programmable interface (API) is improperly protected and can be...
Critical
Unreviewed
CVE-2023-49617
was published
Feb 2, 2024
The cloud provider MachineSense uses for integration and deployment for multiple MachineSense...
High
Unreviewed
CVE-2023-6221
was published
Feb 2, 2024
MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote...
High
Unreviewed
CVE-2023-49115
was published
Feb 2, 2024
Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for...
Moderate
Unreviewed
CVE-2024-22449
was published
Feb 1, 2024
Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records
Moderate
CVE-2020-15136
was published
for
go.etcd.io/etcd
(Go)
Jan 31, 2024
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation...
High
Unreviewed
CVE-2023-6942
was published
Jan 30, 2024
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An...
Critical
Unreviewed
CVE-2024-23618
was published
Jan 26, 2024
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote...
Critical
Unreviewed
CVE-2023-51947
was published
Jan 19, 2024
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to...
Critical
Unreviewed
CVE-2023-5716
was published
Jan 19, 2024
A missing authentication check in the WebSocket channel used for the Check Point IoT integration...
Moderate
Unreviewed
CVE-2023-5253
was published
Jan 15, 2024
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions...
Moderate
Unreviewed
CVE-2023-51062
was published
Jan 13, 2024
NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication...
Moderate
Unreviewed
CVE-2023-31033
was published
Jan 12, 2024
The router console is accessible without authentication at "data" field, and while a user needs...
Critical
Unreviewed
CVE-2023-49255
was published
Jan 12, 2024
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to...
Critical
Unreviewed
CVE-2023-51987
was published
Jan 11, 2024
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to...
Critical
Unreviewed
CVE-2023-51989
was published
Jan 11, 2024
ProTip!
Advisories are also available from the
GraphQL API