GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
491 advisories
Filter by severity
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control...
Critical
Unreviewed
CVE-2025-43983
was published
Aug 14, 2025
Flowise OS command remote code execution
Critical
CVE-2025-8943
was published
for
flowise
(npm)
Aug 14, 2025
Burk Technology ARC Solo's password change mechanism can be utilized without proper ...
Critical
Unreviewed
CVE-2025-5095
was published
Aug 8, 2025
By default, the Packet Power Monitoring and Control Web Interface do not
enforce authentication...
Critical
Unreviewed
CVE-2025-8284
was published
Aug 8, 2025
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote...
Critical
Unreviewed
CVE-2012-10030
was published
Aug 5, 2025
An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System...
Critical
Unreviewed
CVE-2014-125113
was published
Aug 5, 2025
Güralp FMUS series seismic monitoring devices expose an unauthenticated Telnet-based command line...
Critical
Unreviewed
CVE-2025-8286
was published
Jul 31, 2025
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that...
Critical
Unreviewed
CVE-2014-125126
was published
Jul 31, 2025
A Missing Authentication for Critical Function vulnerability in SUSE Manager allows anyone with...
Critical
Unreviewed
CVE-2025-46811
was published
Jul 30, 2025
An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without...
Critical
Unreviewed
CVE-2025-30135
was published
Jul 25, 2025
A remote code execution vulnerability exists in HybridAuth versions 2.0.9 through 2.2.2 due to...
Critical
Unreviewed
CVE-2014-125116
was published
Jul 25, 2025
The embedded web server on the thermostat listed version ranges contain a vulnerability that...
Critical
Unreviewed
CVE-2025-6260
was published
Jul 24, 2025
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station...
Critical
Unreviewed
CVE-2025-34121
was published
Jul 16, 2025
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior...
Critical
Unreviewed
CVE-2025-34104
was published
Jul 15, 2025
An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e...
Critical
Unreviewed
CVE-2025-34068
was published
Jul 15, 2025
An unauthenticated user with management network access can get and
modify the Radiflow iSAP...
Critical
Unreviewed
CVE-2025-3498
was published
Jul 9, 2025
An unrestricted file upload vulnerability in the WordPress Simple File List plugin prior to...
Critical
Unreviewed
CVE-2025-34085
was published
Jul 9, 2025
A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application...
Critical
Unreviewed
CVE-2025-40736
was published
Jul 8, 2025
Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 ...
Critical
Unreviewed
CVE-2025-45814
was published
Jul 2, 2025
A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5...
Critical
Unreviewed
CVE-2025-34070
was published
Jul 2, 2025
An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default...
Critical
Unreviewed
CVE-2025-34069
was published
Jul 2, 2025
A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with...
Critical
Unreviewed
CVE-2025-34071
was published
Jul 2, 2025
An unauthenticated remote attacker can run arbitrary commands on the affected devices with high...
Critical
Unreviewed
CVE-2025-41656
was published
Jul 1, 2025
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated...
Critical
Unreviewed
CVE-2025-5310
was published
Jun 27, 2025
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G...
Critical
Unreviewed
CVE-2025-3699
was published
Jun 27, 2025
ProTip!
Advisories are also available from the
GraphQL API