GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,067
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
501 advisories
Filter by severity
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows...
High
Unreviewed
CVE-2025-8450
was published
Aug 19, 2025
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote...
High
Unreviewed
CVE-2014-9195
was published
May 14, 2022
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde...
High
Unreviewed
CVE-2014-9197
was published
May 17, 2022
Missing Authentication for Critical Function vulnerability in ABB Aspect.This issue affects...
High
Unreviewed
CVE-2025-7677
was published
Aug 11, 2025
A code execution security issue exists in the affected product. An attacker with physical access...
High
Unreviewed
CVE-2025-9160
was published
Sep 9, 2025
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information...
High
Unreviewed
CVE-2023-7308
was published
Aug 28, 2025
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue...
High
Unreviewed
CVE-2025-7635
was published
Sep 9, 2025
A vulnerability has been discovered in AC Smart II where passwords can be changed without...
High
Unreviewed
CVE-2025-10204
was published
Sep 14, 2025
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause...
High
Unreviewed
CVE-2025-8627
was published
Aug 26, 2025
Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function
High
CVE-2025-59358
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly...
High
Unreviewed
CVE-2024-12511
was published
Feb 3, 2025
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of...
High
Unreviewed
CVE-2025-7970
was published
Sep 9, 2025
An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a...
High
Unreviewed
CVE-2025-56562
was published
Sep 16, 2025
GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected...
High
Unreviewed
CVE-2025-9983
was published
Sep 22, 2025
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The...
High
Unreviewed
CVE-2013-10032
was published
Jul 25, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (macOS/Linux client...
High
Unreviewed
CVE-2025-34190
was published
Sep 19, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that...
High
Unreviewed
CVE-2024-45075
was published
Sep 4, 2024
A vulnerability classified as critical was found in Comet System T0510, T3510, T3511, T4511,...
High
Unreviewed
CVE-2025-6763
was published
Jun 27, 2025
The attacker may obtain root access by connecting to the UART port and this vulnerability...
High
Unreviewed
CVE-2025-10991
was published
Sep 30, 2025
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an...
High
Unreviewed
CVE-2025-23293
was published
Sep 30, 2025
WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that returns configuration of the device to...
High
Unreviewed
CVE-2025-3758
was published
May 8, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.1049 and Application...
High
Unreviewed
CVE-2025-34207
was published
Sep 29, 2025
A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel...
High
Unreviewed
CVE-2023-6215
was published
Oct 7, 2025
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service....
High
Unreviewed
CVE-2023-5376
was published
Jan 9, 2024
ProTip!
Advisories are also available from the
GraphQL API