GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
328 advisories
Filter by severity
A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as...
Moderate
Unreviewed
CVE-2024-9513
was published
Oct 4, 2024
By checking the result of calls to `window.open` with specifically set protocol handlers, an...
Moderate
Unreviewed
CVE-2024-9398
was published
Oct 1, 2024
The goTenna Pro has a payload length vulnerability that makes it possible to tell the length of...
Moderate
Unreviewed
CVE-2024-47129
was published
Sep 26, 2024
The goTenna Pro ATAK Plugin has a payload length vulnerability that
makes it possible to tell...
Moderate
Unreviewed
CVE-2024-41715
was published
Sep 26, 2024
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that...
Moderate
Unreviewed
CVE-2024-8651
was published
Sep 19, 2024
Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user...
Moderate
Unreviewed
CVE-2024-23984
was published
Sep 16, 2024
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine...
Moderate
Unreviewed
CVE-2024-34336
was published
Sep 12, 2024
Loway - CWE-204: Observable Response Discrepancy
Moderate
Unreviewed
CVE-2024-42343
was published
Sep 8, 2024
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware...
Moderate
Unreviewed
CVE-2024-45678
was published
Sep 3, 2024
The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against...
Moderate
Unreviewed
CVE-2024-1543
was published
Aug 30, 2024
Generating the ECDSA nonce k samples a random number r and then
truncates this randomness with a...
Moderate
Unreviewed
CVE-2024-1544
was published
Aug 27, 2024
Matrix Tafnit v8
-
CWE-204: Observable Response Discrepancy
Moderate
Unreviewed
CVE-2024-38431
was published
Jul 30, 2024
In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that...
Moderate
Unreviewed
CVE-2024-41880
was published
Jul 22, 2024
In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an...
Moderate
Unreviewed
CVE-2024-39891
was published
Jul 2, 2024
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions...
Moderate
Unreviewed
CVE-2024-36996
was published
Jul 1, 2024
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error...
Moderate
Unreviewed
CVE-2024-38322
was published
Jun 29, 2024
In the Linux kernel, the following vulnerability has been resolved:
dma-buf: heaps: Fix...
Moderate
Unreviewed
CVE-2022-48730
was published
Jun 20, 2024
A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected...
Moderate
Unreviewed
CVE-2024-6129
was published
Jun 18, 2024
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as...
Moderate
Unreviewed
CVE-2024-6056
was published
Jun 17, 2024
Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the...
Moderate
Unreviewed
CVE-2024-38465
was published
Jun 16, 2024
By monitoring the time certain operations take, an attacker could have guessed which external...
Moderate
Unreviewed
CVE-2024-5690
was published
Jun 11, 2024
IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by...
Moderate
Unreviewed
CVE-2024-31878
was published
Jun 7, 2024
A privacy issue was addressed by moving sensitive data to a more secure location. This issue is...
Moderate
Unreviewed
CVE-2024-27839
was published
May 14, 2024
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to...
Moderate
Unreviewed
CVE-2023-27283
was published
May 4, 2024
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames...
Moderate
Unreviewed
CVE-2021-20556
was published
May 3, 2024
ProTip!
Advisories are also available from the
GraphQL API