GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,518
Maven
5,000+
npm
4,156
NuGet
736
pip
3,955
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,252 advisories
Filter by severity
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to...
Critical
Unreviewed
CVE-2023-5716
was published
Jan 19, 2024
A missing authentication check in the WebSocket channel used for the Check Point IoT integration...
Moderate
Unreviewed
CVE-2023-5253
was published
Jan 15, 2024
An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions...
Moderate
Unreviewed
CVE-2023-51062
was published
Jan 13, 2024
NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication...
Moderate
Unreviewed
CVE-2023-31033
was published
Jan 12, 2024
The router console is accessible without authentication at "data" field, and while a user needs...
Critical
Unreviewed
CVE-2023-49255
was published
Jan 12, 2024
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to...
Critical
Unreviewed
CVE-2023-51989
was published
Jan 11, 2024
D-Link DIR-822+ V1.0.2 contains a login bypass in the HNAP1 interface, which allows attackers to...
Critical
Unreviewed
CVE-2023-51987
was published
Jan 11, 2024
An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions)...
High
Unreviewed
CVE-2022-45794
was published
Jan 11, 2024
An authentication issue was addressed with improved state management. This issue is fixed in...
High
Unreviewed
CVE-2023-40393
was published
Jan 11, 2024
Microsoft Bluetooth Driver Spoofing Vulnerability
Moderate
Unreviewed
CVE-2024-21306
was published
Jan 9, 2024
Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect ...
High
Unreviewed
CVE-2023-5881
was published
Jan 3, 2024
An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and...
Critical
Unreviewed
CVE-2023-29485
was published
Dec 21, 2023
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an...
Moderate
Unreviewed
CVE-2023-6368
was published
Dec 14, 2023
In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an...
High
Unreviewed
CVE-2023-6595
was published
Dec 14, 2023
Unauthenticated db-file-storage views
Low
CVE-2023-50263
was published
for
nautobot
(pip)
Dec 13, 2023
An authentication bypass vulnerability has been found in Repox, which allows a remote user to...
Critical
Unreviewed
CVE-2023-6718
was published
Dec 13, 2023
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An...
High
Unreviewed
CVE-2023-32460
was published
Dec 8, 2023
NETGEAR ProSAFE Network Management System has Java Debug Wire Protocol (JDWP) listening on port...
Critical
Unreviewed
CVE-2023-49693
was published
Nov 30, 2023
The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots,...
Low
Unreviewed
CVE-2023-29063
was published
Nov 28, 2023
The FACSChorus workstation operating system does not restrict what devices can interact with its...
Moderate
Unreviewed
CVE-2023-29060
was published
Nov 28, 2023
There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to...
Moderate
Unreviewed
CVE-2023-29061
was published
Nov 28, 2023
Lack of authentication vulnerability. An unauthenticated local user is able to see through the...
Moderate
Unreviewed
CVE-2023-3104
was published
Nov 22, 2023
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet...
Critical
Unreviewed
CVE-2023-42770
was published
Nov 21, 2023
Missing authentication for critical function vulnerability in First Corporation's DVRs allows a...
Critical
Unreviewed
CVE-2023-47674
was published
Nov 16, 2023
VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware...
Critical
Unreviewed
CVE-2023-34060
was published
Nov 14, 2023
ProTip!
Advisories are also available from the
GraphQL API