GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,186 advisories
Filter by severity
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow...
High
Unreviewed
CVE-2019-6198
was published
Jul 31, 2024
A command injection vulnerability could allow an authenticated user to execute operating system...
High
Unreviewed
CVE-2022-4002
was published
Jul 31, 2024
A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow...
High
Unreviewed
CVE-2019-6197
was published
Jul 31, 2024
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to...
High
Unreviewed
CVE-2024-6576
was published
Jul 29, 2024
Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi...
High
Unreviewed
CVE-2024-7050
was published
Jul 26, 2024
Remote command execution due to use of default passwords. The following products are affected:...
Critical
Unreviewed
CVE-2023-45249
was published
Jul 24, 2024
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space...
Low
Unreviewed
CVE-2024-41829
was published
Jul 22, 2024
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution...
Critical
Unreviewed
CVE-2024-23471
was published
Jul 17, 2024
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information...
High
Unreviewed
CVE-2024-28992
was published
Jul 17, 2024
The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass...
High
Unreviewed
CVE-2024-23465
was published
Jul 17, 2024
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote...
Critical
Unreviewed
CVE-2024-23470
was published
Jul 17, 2024
The vulnerability could be remotely exploited to bypass authentication.
Critical
Unreviewed
CVE-2024-22442
was published
Jul 16, 2024
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received...
Moderate
Unreviewed
CVE-2024-39767
was published
Jul 15, 2024
Securepoint UTM before 12.6.5 mishandles OTP codes.
High
Unreviewed
CVE-2024-39340
was published
Jul 12, 2024
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness
An attacker with write access to...
Moderate
Unreviewed
CVE-2024-38433
was published
Jul 11, 2024
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2024-6397
was published
Jul 11, 2024
Sensitive information disclosure in NetScaler Console
Critical
Unreviewed
CVE-2024-6235
was published
Jul 10, 2024
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Moderate
Unreviewed
CVE-2024-38099
was published
Jul 9, 2024
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the...
Moderate
Unreviewed
CVE-2024-39723
was published
Jul 8, 2024
Improper Authentication vulnerability in the mobile monitoring feature of ICONICS GENESIS64...
Moderate
Unreviewed
CVE-2024-1573
was published
Jul 4, 2024
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when...
High
Unreviewed
CVE-2024-39830
was published
Jul 3, 2024
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using...
High
Unreviewed
CVE-2024-3826
was published
Jul 2, 2024
Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass...
High
Unreviewed
CVE-2024-34596
was published
Jul 2, 2024
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers...
Moderate
Unreviewed
CVE-2024-20900
was published
Jul 2, 2024
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to...
Moderate
Unreviewed
CVE-2024-20890
was published
Jul 2, 2024
ProTip!
Advisories are also available from the
GraphQL API