GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,624 advisories
Filter by severity
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies...
Critical
Unreviewed
CVE-2026-2624
was published
Feb 25, 2026
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software...
High
Unreviewed
CVE-2026-2339
was published
Mar 10, 2026
The authentication mechanism for a specific feature in the EasyShare module contains a...
Moderate
Unreviewed
CVE-2025-15515
was published
Mar 13, 2026
An improper access control vulnerability in the canonical-livepatch snap client prior to version...
Moderate
Unreviewed
CVE-2026-6369
was published
Apr 20, 2026
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A...
Critical
Unreviewed
CVE-2025-71318
was published
Jun 5, 2026
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an...
Moderate
Unreviewed
CVE-2026-11238
was published
Jun 5, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PORTY Smart Tech...
High
Unreviewed
CVE-2024-1662
was published
Jun 5, 2024
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software...
Moderate
Unreviewed
CVE-2025-7706
was published
Feb 17, 2026
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in...
Critical
Unreviewed
CVE-2025-8350
was published
Feb 19, 2026
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions...
High
Unreviewed
CVE-2026-36603
was published
Jun 3, 2026
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run...
High
Unreviewed
CVE-2024-27890
was published
Jun 5, 2026
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run...
High
Unreviewed
CVE-2024-27892
was published
Jun 5, 2026
Avation Light Engine Pro exposes its configuration and control interface without any...
Critical
Unreviewed
CVE-2026-1341
was published
Feb 4, 2026
Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution...
Critical
Unreviewed
CVE-2026-25550
was published
Jun 4, 2026
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that...
Critical
Unreviewed
CVE-2019-25738
was published
Jun 4, 2026
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing...
High
Unreviewed
CVE-2026-50225
was published
Jun 4, 2026
Delta Electronics DIAView has multiple vulnerabilities.
Critical
Unreviewed
CVE-2025-62582
was published
Jan 16, 2026
Improper Access Control vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured...
Critical
Unreviewed
CVE-2024-0336
was published
Jun 3, 2024
Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission...
Critical
Unreviewed
CVE-2024-0949
was published
Jun 27, 2024
Improper Privilege Management vulnerability in Menulux Information Technologies Managment Portal...
Moderate
Unreviewed
CVE-2024-4428
was published
Aug 29, 2024
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64...
High
Unreviewed
CVE-2026-8697
was published
May 28, 2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Yordam Information...
High
Unreviewed
CVE-2024-6406
was published
Sep 18, 2024
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization...
High
Unreviewed
CVE-2024-7015
was published
Sep 9, 2024
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be...
Critical
Unreviewed
CVE-2020-27285
was published
May 24, 2022
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions...
Critical
Unreviewed
CVE-2016-9369
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API