GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,475 advisories
Filter by severity
When a master password is set, it is required to be entered again before stored passwords can be...
Moderate
Unreviewed
CVE-2019-11733
was published
May 24, 2022
On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator...
High
Unreviewed
CVE-2021-3297
was published
May 24, 2022
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added...
Critical
Unreviewed
CVE-2018-18505
was published
May 13, 2022
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper...
Critical
Unreviewed
CVE-2025-9803
was published
Nov 25, 2025
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical....
Moderate
Unreviewed
CVE-2025-7897
was published
Jul 20, 2025
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to...
Critical
Unreviewed
CVE-2025-63207
was published
Nov 19, 2025
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is...
Critical
Unreviewed
CVE-2025-63210
was published
Nov 19, 2025
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper...
Critical
Unreviewed
CVE-2025-63224
was published
Nov 19, 2025
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to...
Critical
Unreviewed
CVE-2025-63216
was published
Nov 19, 2025
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It...
Moderate
Unreviewed
CVE-2025-7114
was published
Jul 7, 2025
When multiple server blocks are configured to share the same IP address and port, an attacker can...
Moderate
Unreviewed
CVE-2025-23419
was published
Feb 5, 2025
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6),...
Moderate
Unreviewed
CVE-2022-30229
was published
Jun 15, 2022
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username...
Moderate
Unreviewed
CVE-2025-56764
was published
Sep 29, 2025
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows...
Critical
Unreviewed
CVE-2025-3222
was published
Nov 7, 2025
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD)...
High
Unreviewed
CVE-2023-52161
was published
Feb 22, 2024
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP...
High
Unreviewed
CVE-2025-49812
was published
Jul 10, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2747
was published
Mar 24, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2746
was published
Mar 24, 2025
Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote...
Moderate
Unreviewed
CVE-2014-5412
was published
May 14, 2022
The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS...
Moderate
Unreviewed
CVE-2024-23219
was published
Jan 23, 2024
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate...
High
Unreviewed
CVE-2023-45866
was published
Dec 8, 2023
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit...
Moderate
Unreviewed
CVE-2020-26558
was published
May 24, 2022
The currency dispenser of NCR SelfSev ATMs running APTRA XFS 05.01.00 or earlier does not...
Low
Unreviewed
CVE-2020-10123
was published
May 24, 2022
An authentication issue was addressed with improved state management. This issue is fixed in...
Critical
Unreviewed
CVE-2024-23255
was published
Mar 8, 2024
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a...
Moderate
Unreviewed
CVE-2023-52160
was published
Feb 22, 2024
ProTip!
Advisories are also available from the
GraphQL API