GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
29 advisories
Filter by severity
Hermes improperly validates a JWT
High
CVE-2025-1293
was published
for
github.com/hashicorp-forge/hermes
(Go)
Feb 20, 2025
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged...
High
Unreviewed
CVE-2024-52541
was published
Feb 19, 2025
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing...
Critical
Unreviewed
CVE-2025-1387
was published
Feb 17, 2025
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than...
High
Unreviewed
CVE-2025-26343
was published
Feb 12, 2025
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1,...
High
Unreviewed
CVE-2024-50563
was published
Jan 16, 2025
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0...
Critical
Unreviewed
CVE-2024-48886
was published
Jan 14, 2025
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication...
Critical
Unreviewed
CVE-2024-13239
was published
Jan 9, 2025
Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE...
High
Unreviewed
CVE-2024-47397
was published
Dec 18, 2024
Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue...
Moderate
Unreviewed
CVE-2023-41862
was published
Dec 13, 2024
Active Directory Certificate Services Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49019
was published
Nov 12, 2024
The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication...
Critical
Unreviewed
CVE-2024-45367
was published
Oct 4, 2024
In the goTenna Pro ATAK Plugin there is a vulnerability that makes it
possible to inject any...
Moderate
Unreviewed
CVE-2024-41722
was published
Sep 26, 2024
In the goTenna Pro there is a vulnerability that makes it possible to inject any custom message...
Moderate
Unreviewed
CVE-2024-47127
was published
Sep 26, 2024
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September...
Moderate
Unreviewed
CVE-2024-8322
was published
Sep 10, 2024
Windows Kerberos Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38239
was published
Sep 10, 2024
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate...
Critical
Unreviewed
CVE-2024-38182
was published
Aug 1, 2024
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended...
Low
Unreviewed
CVE-2024-6580
was published
Jul 8, 2024
Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission...
Critical
Unreviewed
CVE-2024-0949
was published
Jun 27, 2024
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection...
Critical
Unreviewed
CVE-2024-34451
was published
Jun 17, 2024
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application,...
Moderate
Unreviewed
CVE-2024-5891
was published
Jun 12, 2024
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-35248
was published
Jun 11, 2024
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor...
High
Unreviewed
CVE-2024-29837
was published
Apr 15, 2024
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011,...
Critical
Unreviewed
CVE-2023-49340
was published
Mar 9, 2024
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation...
Critical
Unreviewed
CVE-2024-0822
was published
Jan 25, 2024
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make...
High
Unreviewed
CVE-2023-4094
was published
Sep 19, 2023
ProTip!
Advisories are also available from the
GraphQL API