GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
246 advisories
Filter by severity
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote,...
High
Unreviewed
CVE-2025-35061
was published
Oct 9, 2025
Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote,...
Moderate
Unreviewed
CVE-2025-35057
was published
Oct 9, 2025
Cognex In-Sight Explorer and In-Sight Camera Firmware expose
a proprietary protocol on TCP port...
High
Unreviewed
CVE-2025-54810
was published
Sep 19, 2025
The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure...
Moderate
Unreviewed
CVE-2025-56448
was published
Sep 15, 2025
A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can...
Moderate
Unreviewed
CVE-2025-8616
was published
Aug 6, 2025
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of...
Moderate
Unreviewed
CVE-2023-50786
was published
Jul 5, 2025
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by...
High
Unreviewed
CVE-2025-36593
was published
Jun 30, 2025
Taylored webhook validation vulnerabilities
Critical
GHSA-8g98-m4j9-qww5
was published
for
taylored
(npm)
Jun 18, 2025
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key...
Critical
Unreviewed
CVE-2025-6029
was published
Jun 13, 2025
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key...
Critical
Unreviewed
CVE-2025-6030
was published
Jun 13, 2025
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
Low
Unreviewed
CVE-2024-38823
was published
Jun 13, 2025
Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote...
Moderate
Unreviewed
CVE-2025-48012
was published
May 21, 2025
Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to...
High
Unreviewed
CVE-2025-30072
was published
May 19, 2025
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal...
Moderate
Unreviewed
CVE-2025-47706
was published
May 14, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix ...
Critical
Unreviewed
CVE-2021-27289
was published
Apr 15, 2025
Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028...
High
Unreviewed
CVE-2024-12137
was published
Mar 19, 2025
SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This...
High
Unreviewed
CVE-2025-1887
was published
Mar 7, 2025
Credential disclosure vulnerability via the /staff route in GreaterWMS <= 2.1.49 allows a remote...
Critical
Unreviewed
CVE-2025-26201
was published
Feb 24, 2025
The login mechanism via device authentication of CGFIDO from Changing Information Technology has...
High
Unreviewed
CVE-2024-12839
was published
Dec 31, 2024
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay...
Moderate
Unreviewed
CVE-2024-52534
was published
Dec 25, 2024
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by...
High
Unreviewed
CVE-2024-49595
was published
Nov 26, 2024
In the development options section of the Settings app, there is a possible authentication bypass...
High
Unreviewed
CVE-2018-9477
was published
Nov 20, 2024
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against...
Low
Unreviewed
CVE-2024-36250
was published
Nov 9, 2024
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which...
High
Unreviewed
CVE-2024-40715
was published
Nov 7, 2024
ProTip!
Advisories are also available from the
GraphQL API