GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID....
High
Unreviewed
CVE-2024-20153
was published
Jan 6, 2025
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in...
Critical
Unreviewed
CVE-2024-45764
was published
Nov 8, 2024
In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id...
Moderate
Unreviewed
CVE-2024-6040
was published
Aug 1, 2024
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an...
High
Unreviewed
CVE-2023-52424
was published
May 17, 2024
Armeria SAML authentication bypass due to missing validation on unsigned SAML messages
Critical
CVE-2024-1735
was published
for
com.linecorp.armeria:armeria-saml
(Maven)
Feb 26, 2024
Infinispan REST Server's cache retrieval endpoints do not properly evaluate the necessary admin permissions
High
CVE-2023-3629
was published
for
org.infinispan:infinispan-server-rest
(Maven)
Dec 30, 2023
Infinispan REST Server's bulk read endpoints do not properly evaluate user permissions
High
CVE-2023-3628
was published
for
org.infinispan:infinispan-server-rest
(Maven)
Dec 30, 2023
Palantir discovered a software bug in a recently released version of Foundry’s Lime2 service, one...
Moderate
Unreviewed
CVE-2023-22833
was published
Jul 6, 2023
Keycloak vulnerable to session takeover with OIDC offline refreshtokens
Moderate
CVE-2022-3916
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 13, 2022
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
High
Unreviewed
CVE-2022-2821
was published
Aug 16, 2022
Websocket requests did not call AuthenticateMethod
Moderate
GHSA-5gjg-jgh4-gppm
was published
for
github.com/ecnepsnai/web
(Go)
Jun 23, 2021
2FA bypass in Wagtail through new device path
Moderate
CVE-2019-16766
was published
for
wagtail-2fa
(pip)
Nov 29, 2019
ProTip!
Advisories are also available from the
GraphQL API