GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
958 advisories
Filter by severity
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5721
was published
Nov 22, 2024
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5718
was published
Nov 22, 2024
A missing authentication for critical function vulnerability has been reported to affect Notes...
Critical
Unreviewed
CVE-2024-38643
was published
Nov 22, 2024
Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System...
High
Unreviewed
CVE-2024-52437
was published
Nov 20, 2024
Missing Authentication for Critical Function vulnerability in deco.Agency de:branding allows...
High
Unreviewed
CVE-2024-52438
was published
Nov 20, 2024
Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware...
Moderate
Unreviewed
CVE-2024-47865
was published
Nov 20, 2024
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated...
Critical
Unreviewed
CVE-2024-0012
was published
Nov 18, 2024
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a...
High
Unreviewed
CVE-2024-41969
was published
Nov 18, 2024
A low privileged remote attacker may modify the boot mode configuration setup of the device,...
High
Unreviewed
CVE-2024-41967
was published
Nov 18, 2024
A low privileged remote attacker may modify the docker settings setup of the device, leading to a...
Moderate
Unreviewed
CVE-2024-41968
was published
Nov 18, 2024
The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to...
Critical
Unreviewed
CVE-2024-10924
was published
Nov 15, 2024
The software tools used by service personnel to test & calibrate the ventilator do not support...
Critical
Unreviewed
CVE-2024-48966
was published
Nov 15, 2024
Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without...
Moderate
Unreviewed
CVE-2024-39707
was published
Nov 15, 2024
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access...
Critical
Unreviewed
CVE-2024-40404
was published
Nov 14, 2024
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access...
High
Unreviewed
CVE-2024-40408
was published
Nov 14, 2024
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows...
High
Unreviewed
CVE-2024-40405
was published
Nov 14, 2024
Missing permission check in Jenkins Script Security Plugin
Moderate
CVE-2024-52549
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Nov 13, 2024
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4...
Moderate
Unreviewed
CVE-2024-26011
was published
Nov 12, 2024
An unauthenticated attacker with access to the local network of the
medical office can query an...
High
Unreviewed
CVE-2024-50589
was published
Nov 8, 2024
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting...
High
Unreviewed
CVE-2024-48953
was published
Nov 7, 2024
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate...
Moderate
Unreviewed
CVE-2024-48952
was published
Nov 7, 2024
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup...
High
Unreviewed
CVE-2024-48950
was published
Nov 7, 2024
The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue...
Moderate
Unreviewed
CVE-2024-51362
was published
Nov 5, 2024
OctoPrint has API key access in settings without reauthentication
Moderate
CVE-2024-51493
was published
for
OctoPrint
(pip)
Nov 5, 2024
The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-9430
was published
Oct 31, 2024
ProTip!
Advisories are also available from the
GraphQL API