GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,150
Maven
5,000+
npm
3,815
NuGet
690
pip
3,490
Pub
12
RubyGems
902
Rust
900
Swift
38
Unreviewed advisories
All unreviewed
5,000+
174 advisories
Filter by severity
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42513
was published
for
OPCFoundation.NetStandard.Opc.Ua.Bindings.Https
(NuGet)
Mar 3, 2025
The application or its infrastructure allows for IP address spoofing by providing its own value...
Moderate
Unreviewed
CVE-2025-22271
was published
Feb 28, 2025
Opera Mini for Android before version 52.2 is vulnerable to an address bar spoofing attack. The...
Moderate
Unreviewed
CVE-2020-6158
was published
Feb 21, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software...
Moderate
Unreviewed
CVE-2023-51326
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking...
Moderate
Unreviewed
CVE-2023-51321
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking...
Moderate
Unreviewed
CVE-2023-51323
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software...
Moderate
Unreviewed
CVE-2023-51327
was published
Feb 20, 2025
Authentication bypass by spoofing issue exists in FileMegane versions above 1.0.0.0 prior to 3.4...
Moderate
Unreviewed
CVE-2025-25055
was published
Feb 18, 2025
Duplicate Advisory: Authentication Bypass by Spoofing in OPC UA .NET Standard Stack
Moderate
GHSA-7wwr-h8cm-9jf7
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Feb 10, 2025
•
withdrawn
The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1...
Moderate
Unreviewed
CVE-2024-36557
was published
Feb 6, 2025
Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing
Moderate
CVE-2024-23953
was published
for
org.apache.hive:hive-llap-common
(Maven)
Jan 28, 2025
Authentication Bypass by Spoofing vulnerability in BestWebSoft Google Captcha allows Identity...
Moderate
Unreviewed
CVE-2025-24628
was published
Jan 27, 2025
Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a...
Moderate
Unreviewed
CVE-2025-0439
was published
Jan 15, 2025
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a...
Moderate
Unreviewed
CVE-2025-0446
was published
Jan 15, 2025
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83...
Moderate
Unreviewed
CVE-2025-0435
was published
Jan 15, 2025
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83...
Moderate
Unreviewed
CVE-2025-0440
was published
Jan 15, 2025
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote...
Moderate
Unreviewed
CVE-2025-0442
was published
Jan 15, 2025
An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing...
Moderate
Unreviewed
CVE-2024-55232
was published
Dec 19, 2024
Authentication Bypass by Spoofing vulnerability in Michal Novák Secure Admin IP allows...
Moderate
Unreviewed
CVE-2023-41133
was published
Dec 13, 2024
The incorrect domain may have been displayed in the address bar during an interrupted navigation...
Moderate
Unreviewed
CVE-2024-11701
was published
Nov 26, 2024
An attacker could cause a select dropdown to be shown over another tab; this could have led to...
Moderate
Unreviewed
CVE-2024-11692
was published
Nov 26, 2024
A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2024-20384
was published
Oct 23, 2024
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software...
Moderate
Unreviewed
CVE-2024-20299
was published
Oct 23, 2024
A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software...
Moderate
Unreviewed
CVE-2024-20297
was published
Oct 23, 2024
QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening...
Moderate
Unreviewed
CVE-2024-49214
was published
Oct 14, 2024
ProTip!
Advisories are also available from the
GraphQL API