GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,221
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,920 advisories
Filter by severity
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker...
Critical
Unreviewed
CVE-2025-9265
was published
Oct 13, 2025
A vulnerability was found in ProjectsAndPrograms School Management System up to...
Moderate
Unreviewed
CVE-2025-11661
was published
Oct 13, 2025
A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is...
Moderate
Unreviewed
CVE-2025-11633
was published
Oct 12, 2025
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to...
Moderate
Unreviewed
CVE-2025-4018
was published
Apr 28, 2025
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to...
Moderate
Unreviewed
CVE-2025-4019
was published
Apr 28, 2025
An attacker with access to the network where the vulnerable device is located could capture...
Moderate
Unreviewed
CVE-2025-2859
was published
Mar 28, 2025
MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
Moderate
CVE-2025-11287
was published
for
@samanhappy/mcphub
(npm)
Oct 5, 2025
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function...
Moderate
Unreviewed
CVE-2025-11529
was published
Oct 9, 2025
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service....
High
Unreviewed
CVE-2023-5376
was published
Jan 9, 2024
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN...
High
Unreviewed
CVE-2025-11192
was published
Oct 7, 2025
Improper Authentication vulnerability in GE Vernova EnerVista UR Setup allows Authentication...
High
Unreviewed
CVE-2025-27254
was published
Mar 10, 2025
An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an...
Moderate
Unreviewed
CVE-2025-54154
was published
Oct 3, 2025
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows...
Critical
Unreviewed
CVE-2024-42462
was published
Aug 16, 2024
Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate...
Critical
Unreviewed
CVE-2025-41064
was published
Oct 2, 2025
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus...
Moderate
Unreviewed
CVE-2025-6533
was published
Jun 26, 2025
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b,...
High
Unreviewed
CVE-2015-7755
was published
May 17, 2022
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username...
Moderate
Unreviewed
CVE-2025-56764
was published
Sep 29, 2025
A vulnerability classified as critical was found in Comet System T0510, T3510, T3511, T4511,...
High
Unreviewed
CVE-2025-6763
was published
Jun 27, 2025
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote...
Critical
Unreviewed
CVE-2025-56752
was published
Sep 29, 2025
IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an...
High
Unreviewed
CVE-2024-27275
was published
Jun 15, 2024
A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the...
High
Unreviewed
CVE-2025-11130
was published
Sep 29, 2025
A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application...
Critical
Unreviewed
CVE-2024-36266
was published
Jun 11, 2024
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication...
Critical
Unreviewed
CVE-2024-8956
was published
Sep 17, 2024
ProTip!
Advisories are also available from the
GraphQL API