GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,874
Erlang
37
GitHub Actions
36
Go
2,520
Maven
5,000+
npm
4,160
NuGet
741
pip
3,961
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,257 advisories
Filter by severity
GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected...
High
Unreviewed
CVE-2025-9983
was published
Sep 22, 2025
Blackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts...
Critical
Unreviewed
CVE-2025-57432
was published
Sep 22, 2025
General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531...
Critical
Unreviewed
CVE-2022-4980
was published
Sep 19, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (macOS/Linux client...
High
Unreviewed
CVE-2025-34190
was published
Sep 19, 2025
Dragonfly doesn't have authentication enabled for some Manager’s endpoints
High
CVE-2025-59345
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing...
Critical
Unreviewed
CVE-2025-9971
was published
Sep 17, 2025
An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a...
High
Unreviewed
CVE-2025-56562
was published
Sep 16, 2025
Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function
High
CVE-2025-59358
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Statistical Database System developed by Gotac has a Missing Authentication vulnerability,...
Critical
Unreviewed
CVE-2025-10452
was published
Sep 15, 2025
A vulnerability has been discovered in AC Smart II where passwords can be changed without...
High
Unreviewed
CVE-2025-10204
was published
Sep 14, 2025
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Critical
CVE-2025-58434
was published
for
flowise
(npm)
Sep 12, 2025
NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing...
Moderate
Unreviewed
CVE-2025-10267
was published
Sep 12, 2025
A missing authentication vulnerability was reported in some Lenovo printers that could allow a...
Moderate
Unreviewed
CVE-2025-9214
was published
Sep 11, 2025
It is possible to bypass the administrator login screen on SolaX Cloud. An attacker could use...
Moderate
Unreviewed
CVE-2025-36757
was published
Sep 10, 2025
A problem with missing authorization on SolaX Cloud platform allows taking over any SolaX...
Moderate
Unreviewed
CVE-2025-36756
was published
Sep 10, 2025
Unauthenticated Telnet access vulnerability in Calix GigaCenter ONT allows root access.This issue...
High
Unreviewed
CVE-2025-7635
was published
Sep 9, 2025
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of...
High
Unreviewed
CVE-2025-7970
was published
Sep 9, 2025
A code execution security issue exists in the affected product. An attacker with physical access...
High
Unreviewed
CVE-2025-9160
was published
Sep 9, 2025
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker...
Moderate
Unreviewed
CVE-2025-42926
was published
Sep 9, 2025
The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a...
Moderate
Unreviewed
CVE-2025-7045
was published
Sep 6, 2025
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated...
Critical
Unreviewed
CVE-2025-8861
was published
Aug 29, 2025
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information...
High
Unreviewed
CVE-2023-7308
was published
Aug 28, 2025
The system exposes several endpoints, typically including "/int/" in their path, that should be...
High
Unreviewed
CVE-2025-30037
was published
Aug 27, 2025
The vulnerability allows unauthenticated users to download a file containing session ID data by...
Critical
Unreviewed
CVE-2025-30040
was published
Aug 27, 2025
The "serverConfig" endpoint, which returns the module configuration including credentials, is...
Moderate
Unreviewed
CVE-2025-30048
was published
Aug 27, 2025
ProTip!
Advisories are also available from the
GraphQL API