GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,778
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
358 advisories
Filter by severity
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This...
High
Unreviewed
CVE-2025-1108
was published
Feb 7, 2025
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access...
Low
Unreviewed
CVE-2025-23415
was published
Feb 5, 2025
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid...
Moderate
Unreviewed
CVE-2025-0510
was published
Feb 4, 2025
There is a vulnerability in the BMC firmware image authentication design
at Supermicro MBD...
High
Unreviewed
CVE-2024-10237
was published
Feb 4, 2025
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-54111
was published
Dec 12, 2024
WildFly Elytron OpenID Connect Client Extension authorization code injection attack
Moderate
CVE-2024-12369
was published
for
org.wildfly:wildfly-elytron-oidc-client-subsystem
(Maven)
Dec 9, 2024
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing...
Moderate
Unreviewed
CVE-2024-52548
was published
Dec 3, 2024
quic-go affected by an ICMP Packet Too Large Injection Attack on Linux
Moderate
CVE-2024-53259
was published
for
github.com/quic-go/quic-go
(Go)
Dec 2, 2024
sigstore-java has vulnerability with bundle verification
Moderate
CVE-2024-53267
was published
for
dev.sigstore:sigstore-java
(Maven)
Nov 26, 2024
IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a...
Moderate
Unreviewed
CVE-2022-33861
was published
Nov 25, 2024
OpenStack Neutron can use an incorrect ID during policy enforcement
Moderate
CVE-2024-53916
was published
for
neutron
(pip)
Nov 25, 2024
Affected devices beacon to eCharge cloud infrastructure asking if there are any command they...
Critical
Unreviewed
CVE-2024-11666
was published
Nov 25, 2024
Visteon Infotainment VIP MCU Code Insufficient Validation of Data Authenticity Local Privilege...
High
Unreviewed
CVE-2024-8356
was published
Nov 23, 2024
In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges...
Moderate
Unreviewed
CVE-2024-47255
was published
Nov 5, 2024
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data...
Moderate
Unreviewed
CVE-2024-47254
was published
Nov 5, 2024
Laravel Reverb Missing API Signature Verification
High
CVE-2024-50347
was published
for
laravel/reverb
(Composer)
Oct 31, 2024
VULNERABILITY DETAILS
Rockwell Automation used the latest versions of the CVSS scoring system to...
High
Unreviewed
CVE-2024-7847
was published
Oct 14, 2024
Gradio lacks integrity checking on the downloaded FRP client
High
CVE-2024-47867
was published
for
gradio
(pip)
Oct 10, 2024
The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional...
Moderate
Unreviewed
CVE-2024-47123
was published
Sep 26, 2024
The goTenna Pro ATAK Plugin use AES CTR mode for short, encrypted
messages without any...
Moderate
Unreviewed
CVE-2024-43108
was published
Sep 26, 2024
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2024-23922
was published
Sep 23, 2024
HTTP client can manipulate custom HTTP headers that are added by Traefik
Critical
CVE-2024-45410
was published
for
github.com/traefik/traefik
(Go)
Sep 19, 2024
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in...
Moderate
Unreviewed
CVE-2022-4533
was published
Sep 19, 2024
ProTip!
Advisories are also available from the
GraphQL API