GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,532 advisories
Filter by severity
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who...
High
Unreviewed
CVE-2025-55234
was published
Sep 9, 2025
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over...
High
Unreviewed
CVE-2025-53778
was published
Aug 12, 2025
The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6....
High
Unreviewed
CVE-2025-43281
was published
Oct 15, 2025
The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege...
High
Unreviewed
CVE-2025-10293
was published
Oct 15, 2025
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to...
High
Unreviewed
CVE-2025-55340
was published
Oct 14, 2025
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin...
High
Unreviewed
CVE-2020-24029
was published
May 24, 2022
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing...
High
Unreviewed
CVE-2025-9064
was published
Oct 14, 2025
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web...
High
Unreviewed
CVE-2025-9063
was published
Oct 14, 2025
The web server on the AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows...
High
Unreviewed
CVE-2014-2373
was published
May 17, 2022
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service....
High
Unreviewed
CVE-2023-5376
was published
Jan 9, 2024
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN...
High
Unreviewed
CVE-2025-11192
was published
Oct 7, 2025
Improper Authentication vulnerability in GE Vernova EnerVista UR Setup allows Authentication...
High
Unreviewed
CVE-2025-27254
was published
Mar 10, 2025
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b,...
High
Unreviewed
CVE-2015-7755
was published
May 17, 2022
A vulnerability classified as critical was found in Comet System T0510, T3510, T3511, T4511,...
High
Unreviewed
CVE-2025-6763
was published
Jun 27, 2025
IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an...
High
Unreviewed
CVE-2024-27275
was published
Jun 15, 2024
A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the...
High
Unreviewed
CVE-2025-11130
was published
Sep 29, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
High
CVE-2025-54376
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS...
High
Unreviewed
CVE-2025-20160
was published
Sep 24, 2025
A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the...
High
Unreviewed
CVE-2025-10906
was published
Sep 24, 2025
The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01...
High
Unreviewed
CVE-2025-57278
was published
Sep 9, 2025
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to...
High
Unreviewed
CVE-2025-57434
was published
Sep 22, 2025
A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown...
High
Unreviewed
CVE-2025-10672
was published
Sep 18, 2025
Vulnerability of PIN enhancement failures in the screen lock module
Impact: Successful...
High
Unreviewed
CVE-2024-42038
was published
Aug 8, 2024
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26...
High
Unreviewed
CVE-2025-31271
was published
Sep 16, 2025
ProTip!
Advisories are also available from the
GraphQL API