GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
835 advisories
Filter by severity
The affected product is vulnerable to an attacker being able to use commands without providing a...
High
Unreviewed
CVE-2024-49399
was published
Oct 17, 2024
Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1...
High
Unreviewed
CVE-2024-23783
was published
Oct 17, 2024
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions,...
High
Unreviewed
CVE-2024-45844
was published
Oct 16, 2024
Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP...
High
Unreviewed
CVE-2024-5749
was published
Oct 15, 2024
An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing...
Critical
Unreviewed
CVE-2024-45274
was published
Oct 15, 2024
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to...
High
Unreviewed
CVE-2024-45276
was published
Oct 15, 2024
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality,...
Critical
Unreviewed
CVE-2024-9984
was published
Oct 15, 2024
The affected product lacks an authentication check when sending commands to the server via the...
High
Unreviewed
CVE-2024-9137
was published
Oct 14, 2024
LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2024-48777
was published
Oct 11, 2024
An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain...
High
Unreviewed
CVE-2024-48775
was published
Oct 11, 2024
An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2024-48773
was published
Oct 11, 2024
An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information...
High
Unreviewed
CVE-2024-48776
was published
Oct 11, 2024
An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to...
High
Unreviewed
CVE-2024-48768
was published
Oct 11, 2024
An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to...
High
Unreviewed
CVE-2024-48771
was published
Oct 11, 2024
CWE-306: Missing Authentication for Critical Function vulnerability exists that could
cause...
Moderate
Unreviewed
CVE-2024-8530
was published
Oct 11, 2024
An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9,...
Critical
Unreviewed
CVE-2024-9164
was published
Oct 11, 2024
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions...
High
Unreviewed
CVE-2024-9522
was published
Oct 10, 2024
Missing authentication for critical function in Visual Studio Code extension for Arduino allows...
High
Unreviewed
CVE-2024-43488
was published
Oct 8, 2024
Missing Authentication - User & System Configuration
High
Unreviewed
CVE-2024-47555
was published
Oct 7, 2024
TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS...
Critical
Unreviewed
CVE-2024-41988
was published
Oct 3, 2024
An unauthenticated remote attacker may use the devices traffic capture without authentication to...
Moderate
Unreviewed
CVE-2024-35294
was published
Oct 2, 2024
An unauthenticated remote attacker may use a missing authentication for critical function...
Critical
Unreviewed
CVE-2024-35293
was published
Oct 2, 2024
The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2024-9289
was published
Oct 1, 2024
An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web...
Critical
Unreviewed
CVE-2024-42017
was published
Sep 30, 2024
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control....
Critical
Unreviewed
CVE-2024-46293
was published
Sep 30, 2024
ProTip!
Advisories are also available from the
GraphQL API