GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,423 advisories
Filter by severity
Improper Authentication vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main...
Critical
Unreviewed
CVE-2023-4562
was published
Oct 13, 2023
An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The...
Moderate
Unreviewed
CVE-2023-41261
was published
Oct 13, 2023
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local...
High
Unreviewed
CVE-2023-23632
was published
Oct 12, 2023
An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325...
Critical
Unreviewed
CVE-2023-24479
was published
Oct 11, 2023
Vulnerability of brute-force attacks on the device authentication module.Successful exploitation...
High
Unreviewed
CVE-2023-44096
was published
Oct 11, 2023
Sensitive information disclosure and manipulation due to improper authentication. The following...
High
Unreviewed
CVE-2023-45246
was published
Oct 6, 2023
Garuda Linux performs an insecure user creation and authentication that allows any user to...
High
Unreviewed
CVE-2021-3784
was published
Oct 4, 2023
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under...
Moderate
Unreviewed
CVE-2023-40376
was published
Oct 4, 2023
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
High
Unreviewed
CVE-2023-28540
was published
Oct 3, 2023
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310...
High
Unreviewed
CVE-2023-42771
was published
Oct 3, 2023
A vulnerability classified as critical has been found in SATO CL4NX-J Plus 1.13.2-u455_r2. This...
Moderate
Unreviewed
CVE-2023-5328
was published
Oct 2, 2023
A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This...
Moderate
Unreviewed
CVE-2023-5329
was published
Oct 2, 2023
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical....
Moderate
Unreviewed
CVE-2023-5326
was published
Oct 2, 2023
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN...
Critical
Unreviewed
CVE-2023-20252
was published
Sep 27, 2023
Sensitive information disclosure and manipulation due to improper authentication. The following...
Moderate
Unreviewed
CVE-2023-44152
was published
Sep 27, 2023
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST...
Moderate
Unreviewed
CVE-2023-41904
was published
Sep 27, 2023
An Innsertion of Sensitive Information into Log File vulnerability in SUSE SUSE Manager Server...
High
Unreviewed
CVE-2023-22644
was published
Sep 20, 2023
NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as...
High
Unreviewed
CVE-2023-31015
was published
Sep 20, 2023
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make...
High
Unreviewed
CVE-2023-4094
was published
Sep 19, 2023
The vulnerability exists in Uniview IP Camera due to identification and authentication failure at...
Critical
Unreviewed
CVE-2023-0773
was published
Sep 19, 2023
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki...
High
Unreviewed
CVE-2023-0813
was published
Sep 15, 2023
An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL...
High
Unreviewed
CVE-2022-47848
was published
Sep 15, 2023
A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901....
Moderate
Unreviewed
CVE-2023-4985
was published
Sep 15, 2023
** UNSUPPPORTED WHEN ASSIGNED ** Authentication Bypass by Assumed-Immutable Data vulnerability in...
Critical
Unreviewed
CVE-2023-4669
was published
Sep 14, 2023
PaperCut NG allows for unauthenticated XMLRPC commands to be run by default. Versions 22.0.12 and...
Moderate
Unreviewed
CVE-2023-4568
was published
Sep 13, 2023
ProTip!
Advisories are also available from the
GraphQL API