GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,244 advisories
Filter by severity
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Critical
CVE-2025-58434
was published
for
flowise
(npm)
Sep 12, 2025
NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing...
Moderate
Unreviewed
CVE-2025-10267
was published
Sep 12, 2025
A missing authentication vulnerability was reported in some Lenovo printers that could allow a...
Moderate
Unreviewed
CVE-2025-9214
was published
Sep 11, 2025
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use...
Moderate
Unreviewed
CVE-2025-36757
was published
Sep 10, 2025
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX...
Moderate
Unreviewed
CVE-2025-36756
was published
Sep 10, 2025
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue...
High
Unreviewed
CVE-2025-7635
was published
Sep 9, 2025
A code execution security issue exists in the affected product. An attacker with physical access...
High
Unreviewed
CVE-2025-9160
was published
Sep 9, 2025
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of...
High
Unreviewed
CVE-2025-7970
was published
Sep 9, 2025
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker...
Moderate
Unreviewed
CVE-2025-42926
was published
Sep 9, 2025
The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a...
Moderate
Unreviewed
CVE-2025-7045
was published
Sep 6, 2025
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2025-8861
was published
Aug 29, 2025
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information...
High
Unreviewed
CVE-2023-7308
was published
Aug 28, 2025
Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows...
Critical
Unreviewed
CVE-2025-30039
was published
Aug 27, 2025
The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat...
Critical
Unreviewed
CVE-2025-30041
was published
Aug 27, 2025
The vulnerability allows unauthenticated users to download a file containing session ID data by...
Critical
Unreviewed
CVE-2025-30040
was published
Aug 27, 2025
The system exposes several endpoints, typically including "/int/" in their path, that should be...
High
Unreviewed
CVE-2025-30037
was published
Aug 27, 2025
The "serverConfig" endpoint, which returns the module configuration including credentials, is...
Moderate
Unreviewed
CVE-2025-30048
was published
Aug 27, 2025
Kapsch TrafficCom RIS-9260 RSU LEO v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 were...
Critical
Unreviewed
CVE-2025-25736
was published
Aug 26, 2025
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause...
High
Unreviewed
CVE-2025-8627
was published
Aug 26, 2025
An authentication bypass vulnerability exists which allows an unauthenticated attacker to control...
Critical
Unreviewed
CVE-2025-53118
was published
Aug 26, 2025
WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2025-9254
was published
Aug 22, 2025
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro...
Critical
Unreviewed
CVE-2025-27214
was published
Aug 21, 2025
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution...
Critical
Unreviewed
CVE-2025-8611
was published
Aug 20, 2025
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution...
Critical
Unreviewed
CVE-2025-8610
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API