GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,897 advisories
Filter by severity
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate...
Moderate
Unreviewed
CVE-2025-25451
was published
Mar 6, 2025
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to...
Moderate
Unreviewed
CVE-2025-25450
was published
Mar 6, 2025
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to...
Moderate
Unreviewed
CVE-2025-25452
was published
Mar 6, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27672
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368...
Critical
Unreviewed
CVE-2025-27641
was published
Mar 5, 2025
Scanning certain QR codes that included text with a website URL could allow the URL to be opened...
Moderate
Unreviewed
CVE-2025-27425
was published
Mar 4, 2025
A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been classified as...
Low
Unreviewed
CVE-2025-1880
was published
Mar 3, 2025
MinIO allows an SFTP authentication bypass due to improperly trusted SSH key
Moderate
CVE-2025-27414
was published
for
github.com/minio/minio
(Go)
Mar 3, 2025
While processing the authentication message in UE, improper authentication may lead to...
Moderate
Unreviewed
CVE-2024-38426
was published
Mar 3, 2025
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account...
High
Unreviewed
CVE-2025-1723
was published
Mar 3, 2025
An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge...
Critical
Unreviewed
CVE-2025-23116
was published
Mar 1, 2025
A vulnerability in the remote connection complements of the NVDA (Nonvisual Desktop Access) 2024...
High
Unreviewed
CVE-2025-26326
was published
Feb 28, 2025
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Navidrome allows an authentication bypass in Subsonic API with non-existent username
Moderate
CVE-2025-27112
was published
for
github.com/navidrome/navidrome
(Go)
Feb 25, 2025
A flaw in Gliffy results in broken authentication through the reset functionality of the...
Moderate
Unreviewed
CVE-2024-5174
was published
Feb 24, 2025
A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary...
High
Unreviewed
CVE-2025-1024
was published
Feb 19, 2025
The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and...
Critical
Unreviewed
CVE-2022-41545
was published
Feb 18, 2025
A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier...
Critical
Unreviewed
CVE-2024-57049
was published
Feb 18, 2025
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits...
Critical
Unreviewed
CVE-2024-57045
was published
Feb 18, 2025
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits...
High
Unreviewed
CVE-2024-57046
was published
Feb 18, 2025
A vulnerability in the TP-Link WR840N v6 router with firmware version 0.9.1 4.16 and earlier...
Critical
Unreviewed
CVE-2024-57050
was published
Feb 18, 2025
A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's...
High
Unreviewed
CVE-2025-0981
was published
Feb 18, 2025
Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of...
Critical
Unreviewed
CVE-2025-1298
was published
Feb 14, 2025
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13528
was published
Feb 12, 2025
An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate...
Moderate
Unreviewed
CVE-2024-54916
was published
Feb 12, 2025
ProTip!
Advisories are also available from the
GraphQL API