GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
881 advisories
Filter by severity
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper...
Critical
Unreviewed
CVE-2025-9803
was published
Nov 25, 2025
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is...
Critical
Unreviewed
CVE-2025-63210
was published
Nov 19, 2025
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to...
Critical
Unreviewed
CVE-2025-63207
was published
Nov 19, 2025
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper...
Critical
Unreviewed
CVE-2025-63224
was published
Nov 19, 2025
The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to...
Critical
Unreviewed
CVE-2025-63216
was published
Nov 19, 2025
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows...
Critical
Unreviewed
CVE-2025-3222
was published
Nov 7, 2025
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper...
Critical
Unreviewed
CVE-2025-43995
was published
Oct 24, 2025
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
Critical
Unreviewed
CVE-2025-56447
was published
Oct 22, 2025
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an...
Critical
Unreviewed
CVE-2025-41108
was published
Oct 22, 2025
Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017,...
Critical
Unreviewed
CVE-2025-60772
was published
Oct 21, 2025
Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that...
Critical
Unreviewed
CVE-2025-11625
was published
Oct 21, 2025
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker...
Critical
Unreviewed
CVE-2025-9265
was published
Oct 13, 2025
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component:...
Critical
Unreviewed
CVE-2025-61882
was published
Oct 5, 2025
Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate...
Critical
Unreviewed
CVE-2025-41064
was published
Oct 2, 2025
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote...
Critical
Unreviewed
CVE-2025-56752
was published
Sep 29, 2025
Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to...
Critical
Unreviewed
CVE-2025-9965
was published
Sep 23, 2025
Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0...
Critical
Unreviewed
CVE-2025-45583
was published
Sep 12, 2025
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application....
Critical
Unreviewed
CVE-2025-10365
was published
Sep 12, 2025
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an...
Critical
Unreviewed
CVE-2025-9994
was published
Sep 9, 2025
Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1...
Critical
Unreviewed
CVE-2023-21467
was published
Sep 8, 2025
Azure Entra Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2025-55241
was published
Sep 5, 2025
An improper authentication vulnerability has been reported to affect VioStor. If a remote...
Critical
Unreviewed
CVE-2025-52856
was published
Aug 29, 2025
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to...
Critical
Unreviewed
CVE-2025-7955
was published
Aug 28, 2025
MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this...
Critical
Unreviewed
CVE-2024-50645
was published
Aug 22, 2025
zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can...
Critical
Unreviewed
CVE-2024-50644
was published
Aug 22, 2025
ProTip!
Advisories are also available from the
GraphQL API