GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,952
Erlang
39
GitHub Actions
38
Go
2,609
Maven
5,000+
npm
4,252
NuGet
757
pip
4,023
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
487 advisories
Filter by severity
microCLAUDIA in v3.2.0 and prior has an improper access control vulnerability.
This flaw allows...
High
Unreviewed
CVE-2025-41090
was published
Oct 28, 2025
Dell Storage Center - Dell Storage Manager, version(s) DSM 20.1.21, contain(s) a Missing...
High
Unreviewed
CVE-2025-43994
was published
Oct 24, 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
High
Unreviewed
CVE-2025-61752
was published
Oct 21, 2025
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of...
High
Unreviewed
CVE-2025-61756
was published
Oct 22, 2025
XStream is vulnerable to a Remote Command Execution attack
High
CVE-2021-39144
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Aug 25, 2021
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated...
High
Unreviewed
CVE-2025-0108
was published
Feb 12, 2025
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting...
High
Unreviewed
CVE-2025-24472
was published
Feb 11, 2025
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the...
High
Unreviewed
CVE-2023-27532
was published
Mar 11, 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
High
Unreviewed
CVE-2023-21839
was published
Jan 18, 2023
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same...
High
Unreviewed
CVE-2020-24363
was published
May 24, 2022
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not...
High
Unreviewed
CVE-2020-6287
was published
May 24, 2022
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote...
High
Unreviewed
CVE-2019-9082
was published
May 13, 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative...
High
Unreviewed
CVE-2022-24990
was published
Feb 7, 2023
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent:...
High
Unreviewed
CVE-2017-10271
was published
May 13, 2022
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions,...
High
Unreviewed
CVE-2024-45844
was published
Oct 16, 2024
EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication...
High
Unreviewed
CVE-2025-11949
was published
Oct 21, 2025
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an...
High
Unreviewed
CVE-2022-37062
was published
Aug 19, 2022
OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password....
High
Unreviewed
CVE-2025-62586
was published
Oct 16, 2025
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows...
High
Unreviewed
CVE-2024-9919
was published
Mar 20, 2025
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows...
High
Unreviewed
CVE-2024-6842
was published
Mar 20, 2025
NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of...
High
Unreviewed
CVE-2025-23356
was published
Oct 14, 2025
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization...
High
Unreviewed
CVE-2024-7015
was published
Sep 9, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PORTY Smart Tech...
High
Unreviewed
CVE-2024-1662
was published
Jun 5, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Yordam Information...
High
Unreviewed
CVE-2024-6406
was published
Sep 18, 2024
ProTip!
Advisories are also available from the
GraphQL API