GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,423 advisories
Filter by severity
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term...
Moderate
Unreviewed
CVE-2023-21307
was published
Oct 30, 2023
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This...
High
Unreviewed
CVE-2023-5830
was published
Oct 27, 2023
A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an...
Moderate
Unreviewed
CVE-2022-3681
was published
Oct 27, 2023
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal...
High
Unreviewed
CVE-2023-35794
was published
Oct 27, 2023
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain...
High
Unreviewed
CVE-2023-46290
was published
Oct 27, 2023
Standard users can directly operate and set printer configuration information , such as IP, in...
Moderate
Unreviewed
CVE-2022-34887
was published
Oct 27, 2023
Under a very specific and highly unrecommended configuration, authentication bypass is possible...
Critical
Unreviewed
CVE-2023-37283
was published
Oct 25, 2023
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb...
High
Unreviewed
CVE-2023-27376
was published
Oct 25, 2023
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb...
High
Unreviewed
CVE-2023-27375
was published
Oct 25, 2023
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and...
Moderate
Unreviewed
CVE-2023-27256
was published
Oct 25, 2023
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1...
High
Unreviewed
CVE-2023-27257
was published
Oct 25, 2023
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in...
High
Unreviewed
CVE-2023-27377
was published
Oct 25, 2023
Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052...
High
Unreviewed
CVE-2023-26576
was published
Oct 25, 2023
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1...
High
Unreviewed
CVE-2023-27259
was published
Oct 25, 2023
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application...
High
Unreviewed
CVE-2023-27258
was published
Oct 25, 2023
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3...
Moderate
Unreviewed
CVE-2023-27261
was published
Oct 25, 2023
Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052...
High
Unreviewed
CVE-2023-26575
was published
Oct 25, 2023
Missing authentication in the SetDB method in IDAttend’s IDWeb application 3.1.052 and earlier...
Critical
Unreviewed
CVE-2023-26573
was published
Oct 25, 2023
Missing authentication in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb...
High
Unreviewed
CVE-2023-26570
was published
Oct 25, 2023
Missing authentication in the SetStudentNotes method in IDAttend’s IDWeb application 3.1.052 and...
High
Unreviewed
CVE-2023-26571
was published
Oct 25, 2023
Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and...
High
Unreviewed
CVE-2023-26574
was published
Oct 25, 2023
Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073,...
High
Unreviewed
CVE-2023-5246
was published
Oct 23, 2023
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass...
Moderate
Unreviewed
CVE-2023-38735
was published
Oct 22, 2023
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and...
Moderate
Unreviewed
CVE-2023-4939
was published
Oct 21, 2023
The affected product is vulnerable to an improper authentication vulnerability, which...
High
Unreviewed
CVE-2023-41089
was published
Oct 19, 2023
ProTip!
Advisories are also available from the
GraphQL API