GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,270 advisories
Filter by severity
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
High
Unreviewed
CVE-2024-1609
was published
Dec 25, 2024
The AirVantage platform is vulnerable to an unauthorized attacker registering previously...
High
Unreviewed
CVE-2023-31279
was published
Dec 21, 2024
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
High
Unreviewed
CVE-2024-1610
was published
Dec 18, 2024
Vulnerability of lax app identity verification in the pre-authorization function.Successful...
High
Unreviewed
CVE-2022-48496
was published
Jun 19, 2023
Vulnerability of lax app identity verification in the pre-authorization function.Successful...
High
Unreviewed
CVE-2022-48494
was published
Jun 19, 2023
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before...
High
Unreviewed
CVE-2024-2450
was published
Mar 15, 2024
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate...
High
Unreviewed
CVE-2023-45866
was published
Dec 8, 2023
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-10111
was published
Dec 12, 2024
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49076
was published
Dec 12, 2024
NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker...
High
Unreviewed
CVE-2024-0130
was published
Dec 6, 2024
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User...
High
Unreviewed
CVE-2024-11293
was published
Dec 4, 2024
A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower...
High
Unreviewed
CVE-2020-3410
was published
May 24, 2022
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local...
High
Unreviewed
CVE-2016-6434
was published
May 17, 2022
Initial xbl_sec revision does not have all the debug policy features and critical checks.
High
Unreviewed
CVE-2016-10394
was published
Nov 26, 2024
An image with a version lower than the fuse version may potentially be booted lead to improper...
High
Unreviewed
CVE-2018-11952
was published
Nov 26, 2024
Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2024-6248
was published
Nov 22, 2024
**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL...
High
Unreviewed
CVE-2024-11494
was published
Nov 20, 2024
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT'...
High
Unreviewed
CVE-2020-12627
was published
May 24, 2022
An Innsertion of Sensitive Information into Log File vulnerability in SUSE SUSE Manager Server...
High
Unreviewed
CVE-2023-22644
was published
Sep 20, 2023
Windows Task Scheduler Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49039
was published
Nov 12, 2024
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress...
High
Unreviewed
CVE-2024-9946
was published
Nov 6, 2024
The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in...
High
Unreviewed
CVE-2024-10020
was published
Nov 6, 2024
Waybox Enel X web management API authentication could be bypassed and provide administrator’s...
High
Unreviewed
CVE-2023-29117
was published
Nov 5, 2024
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all...
High
Unreviewed
CVE-2024-10114
was published
Nov 5, 2024
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication...
High
Unreviewed
CVE-2024-10097
was published
Nov 5, 2024
ProTip!
Advisories are also available from the
GraphQL API