GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,829
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
388 advisories
Filter by severity
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup...
High
Unreviewed
CVE-2025-27256
was published
Mar 10, 2025
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege...
High
Unreviewed
CVE-2024-9658
was published
Mar 7, 2025
Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular...
High
Unreviewed
CVE-2024-31525
was published
Mar 5, 2025
The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to,...
High
Unreviewed
CVE-2025-1717
was published
Feb 27, 2025
Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-21355
was published
Feb 20, 2025
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated...
High
Unreviewed
CVE-2025-0108
was published
Feb 12, 2025
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free...
High
Unreviewed
CVE-2025-26362
was published
Feb 12, 2025
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free...
High
Unreviewed
CVE-2025-26366
was published
Feb 12, 2025
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free...
High
Unreviewed
CVE-2025-26365
was published
Feb 12, 2025
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free...
High
Unreviewed
CVE-2025-26363
was published
Feb 12, 2025
A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free...
High
Unreviewed
CVE-2025-26364
was published
Feb 12, 2025
A file handling command vulnerability in certain versions of Armoury Crate may result in...
High
Unreviewed
CVE-2024-12957
was published
Jan 23, 2025
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web...
High
Unreviewed
CVE-2025-21515
was published
Jan 21, 2025
Nedap Librix Ecoreader
is missing authentication for critical functions that could allow an ...
High
Unreviewed
CVE-2024-12757
was published
Jan 17, 2025
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver...
High
Unreviewed
CVE-2025-0355
was published
Jan 15, 2025
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0...
High
Unreviewed
CVE-2024-35277
was published
Jan 14, 2025
Locally installed application can bypass the permission check and perform system operations that...
High
Unreviewed
CVE-2021-26280
was published
Dec 17, 2024
Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of...
High
Unreviewed
CVE-2024-10774
was published
Dec 6, 2024
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via...
High
Unreviewed
CVE-2024-10776
was published
Dec 6, 2024
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a...
High
Unreviewed
CVE-2024-42456
was published
Dec 4, 2024
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting...
High
Unreviewed
CVE-2024-42455
was published
Dec 4, 2024
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to...
High
Unreviewed
CVE-2024-40717
was published
Dec 4, 2024
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and...
High
Unreviewed
CVE-2024-50381
was published
Dec 2, 2024
Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to...
High
Unreviewed
CVE-2024-53623
was published
Nov 30, 2024
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an...
High
Unreviewed
CVE-2024-49052
was published
Nov 26, 2024
ProTip!
Advisories are also available from the
GraphQL API