GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,416
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66...
High
Unreviewed
CVE-2025-44557
was published
Jun 27, 2025
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE...
High
Unreviewed
CVE-2024-34722
was published
Jul 9, 2024
D-Link DIR-X3260 prog.cgi Incorrect Implementation of Authentication Algorithm Authentication...
High
Unreviewed
CVE-2023-44420
was published
May 3, 2024
D-Link DIR-2150 LoginPassword Incorrect Implementation of Authentication Algorithm Authentication...
High
Unreviewed
CVE-2023-34274
was published
May 3, 2024
D-Link DIR-2150 HNAP Incorrect Implementation of Authentication Algorithm Authentication Bypass...
High
Unreviewed
CVE-2023-34282
was published
May 3, 2024
Windows Kerberos Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26248
was published
Apr 9, 2024
Eclipse Kura LogServlet vulnerability
High
CVE-2024-3046
was published
for
org.eclipse.kura:org.eclipse.kura.web2
(Maven)
Apr 9, 2024
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow...
High
Unreviewed
CVE-2021-42146
was published
Jan 24, 2024
Insufficient authentication flow in Checkmk before 2.2.0p17, 2.1.0p37 and 2.0.0p39 allows...
High
Unreviewed
CVE-2023-31211
was published
Jan 12, 2024
An authentication bypass vulnerability exists in the Authentication functionality of Weston...
High
Unreviewed
CVE-2022-41985
was published
May 10, 2023
Prometheus vulnerable to basic authentication bypass
High
GHSA-4v48-4q5m-8vx4
was published
for
github.com/prometheus/prometheus
(Go)
Dec 5, 2022
A vulnerability has been identified in Opcenter Quality V13.1 (All versions < V13.1.20220624),...
High
Unreviewed
CVE-2022-33736
was published
Jul 13, 2022
Saltstack Salt Unauthenticated Arbitrary Code Execution
High
CVE-2021-25315
was published
for
salt
(pip)
May 24, 2022
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer...
High
Unreviewed
CVE-2016-9463
was published
May 13, 2022
Auto-merging Person Records Compromised
High
CVE-2021-32691
was published
for
@apollosproject/data-connector-rock
(npm)
Jun 21, 2021
ProTip!
Advisories are also available from the
GraphQL API