GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there...
Moderate
Unreviewed
CVE-2025-32885
was published
May 2, 2025
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The app there...
Moderate
Unreviewed
CVE-2025-32883
was published
May 2, 2025
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email...
High
Unreviewed
CVE-2025-31676
was published
Apr 1, 2025
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP allows Privilege Escalation. This...
Critical
Unreviewed
CVE-2025-39596
was published
Apr 17, 2025
Weak authentication in Windows Active Directory Certificate Services allows an authorized...
High
Unreviewed
CVE-2025-27740
was published
Apr 8, 2025
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature...
Moderate
Unreviewed
CVE-2025-26635
was published
Apr 8, 2025
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions),...
Critical
Unreviewed
CVE-2024-54092
was published
Apr 8, 2025
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes...
Moderate
Unreviewed
CVE-2024-45551
was published
Apr 7, 2025
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol...
Low
Unreviewed
CVE-2025-29991
was published
Apr 3, 2025
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in...
Critical
Unreviewed
CVE-2024-39848
was published
Jun 30, 2024
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass...
High
Unreviewed
CVE-2024-36787
was published
Jun 7, 2024
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low...
High
Unreviewed
CVE-2025-23058
was published
Feb 4, 2025
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards ...
Moderate
Unreviewed
CVE-2025-21552
was published
Jan 21, 2025
This vulnerability exists in the CAP back office application due to improper authentication check...
High
Unreviewed
CVE-2025-29994
was published
Mar 13, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
High
CVE-2025-24070
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2025
Hermes improperly validates a JWT
High
CVE-2025-1293
was published
for
github.com/hashicorp-forge/hermes
(Go)
Feb 20, 2025
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged...
High
Unreviewed
CVE-2024-52541
was published
Feb 19, 2025
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing...
Critical
Unreviewed
CVE-2025-1387
was published
Feb 17, 2025
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than...
High
Unreviewed
CVE-2025-26343
was published
Feb 12, 2025
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1,...
High
Unreviewed
CVE-2024-50563
was published
Jan 16, 2025
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0...
Critical
Unreviewed
CVE-2024-48886
was published
Jan 14, 2025
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication...
Critical
Unreviewed
CVE-2024-13239
was published
Jan 9, 2025
Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE...
High
Unreviewed
CVE-2024-47397
was published
Dec 18, 2024
Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue...
Moderate
Unreviewed
CVE-2023-41862
was published
Dec 13, 2024
Active Directory Certificate Services Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49019
was published
Nov 12, 2024
ProTip!
Advisories are also available from the
GraphQL API