GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,811
Erlang
36
GitHub Actions
32
Go
2,396
Maven
5,000+
npm
4,033
NuGet
721
pip
3,824
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
43 advisories
Filter by severity
The AXIS Camera Station Server had a flaw that allowed
to bypass authentication that is normally...
Moderate
Unreviewed
CVE-2025-30026
was published
Jul 11, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA -...
Moderate
Unreviewed
CVE-2025-6675
was published
Jun 26, 2025
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a...
Moderate
Unreviewed
CVE-2025-6556
was published
Jun 24, 2025
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-5820
was published
Jun 23, 2025
Vulnerability that cards can call unauthorized APIs in the FRS process
Impact: Successful...
Moderate
Unreviewed
CVE-2025-48904
was published
Jun 6, 2025
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover...
Moderate
Unreviewed
CVE-2025-48926
was published
May 28, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48010
was published
May 21, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48011
was published
May 21, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo -...
Moderate
Unreviewed
CVE-2024-33939
was published
May 19, 2025
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and...
Moderate
Unreviewed
CVE-2025-4427
was published
May 13, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to...
Moderate
Unreviewed
CVE-2025-0549
was published
May 9, 2025
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to...
Moderate
Unreviewed
CVE-2025-32357
was published
Apr 5, 2025
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2024-13772
was published
Mar 14, 2025
Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password...
Moderate
Unreviewed
CVE-2025-26700
was published
Feb 17, 2025
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication...
Moderate
Unreviewed
CVE-2025-24456
was published
Jan 21, 2025
IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By...
Moderate
Unreviewed
CVE-2024-51464
was published
Dec 21, 2024
IBM Cognos Controller 11.0.0 and 11.0.1
could allow an authenticated user with local access...
Moderate
Unreviewed
CVE-2024-25036
was published
Dec 3, 2024
The web server of affected devices do not properly authenticate user request to the '/ClientArea...
Moderate
Unreviewed
CVE-2024-46887
was published
Oct 8, 2024
IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive...
Moderate
Unreviewed
CVE-2024-35151
was published
Aug 22, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics...
Moderate
Unreviewed
CVE-2024-5620
was published
Jul 18, 2024
The affected product is vulnerable to an attacker modifying the bootloader by using custom...
Moderate
Unreviewed
CVE-2024-38279
was published
Jun 13, 2024
An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that...
Moderate
Unreviewed
CVE-2023-50915
was published
Apr 30, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16...
Moderate
Unreviewed
CVE-2024-1525
was published
Feb 22, 2024
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA)...
Moderate
Unreviewed
CVE-2023-20247
was published
Nov 1, 2023
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring...
Moderate
Unreviewed
CVE-2023-39231
was published
Oct 25, 2023
ProTip!
Advisories are also available from the
GraphQL API