GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,298
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
285 advisories
Filter by severity
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept...
High
Unreviewed
CVE-2022-47522
was published
Apr 15, 2023
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass.This...
Critical
Unreviewed
CVE-2023-2887
was published
May 25, 2023
A lack of in app notification for entering fullscreen mode could have lead to a malicious website...
High
Unreviewed
CVE-2023-25743
was published
Jun 2, 2023
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS...
Critical
Unreviewed
CVE-2023-2807
was published
Jun 13, 2023
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this...
Moderate
Unreviewed
CVE-2022-48469
was published
Jun 16, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34158
was published
Jun 19, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34160
was published
Jun 19, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34167
was published
Jun 19, 2023
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For...
Critical
Unreviewed
CVE-2021-25827
was published
Jun 28, 2023
An authentication bypass issue via spoofing was discovered in the token-based authentication...
Critical
Unreviewed
CVE-2023-22814
was published
Jul 1, 2023
Vulnerability of identity verification being bypassed in the Gallery module. Successful...
Critical
Unreviewed
CVE-2022-48513
was published
Jul 6, 2023
A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate...
High
Unreviewed
CVE-2022-32747
was published
Jul 6, 2023
AMI SPx contains a vulnerability in BMC where a User may cause an authentication bypass by...
High
Unreviewed
CVE-2023-34329
was published
Jul 18, 2023
The foundry campaigns service was found to be vulnerable to an unauthenticated information...
Moderate
Unreviewed
CVE-2023-30950
was published
Aug 4, 2023
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from...
Moderate
Unreviewed
CVE-2022-1601
was published
Aug 30, 2023
This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from...
High
Unreviewed
CVE-2023-4279
was published
Sep 4, 2023
The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to...
Moderate
Unreviewed
CVE-2023-4631
was published
Sep 25, 2023
This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially...
Moderate
Unreviewed
CVE-2023-4281
was published
Sep 25, 2023
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication...
Critical
Unreviewed
CVE-2023-30803
was published
Oct 10, 2023
This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from...
High
Unreviewed
CVE-2023-5133
was published
Oct 16, 2023
An authentication bypass by spoofing of a device with a synthetic IP address is possible in...
Moderate
Unreviewed
CVE-2023-28803
was published
Oct 23, 2023
By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it...
Unknown
Unreviewed
CVE-2024-29006
was published
Apr 4, 2024
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to...
Moderate
Unreviewed
CVE-2021-22890
was published
May 24, 2022
A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions),...
Moderate
Unreviewed
CVE-2024-30189
was published
Apr 9, 2024
A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748...
High
Unreviewed
CVE-2024-30191
was published
Apr 9, 2024
ProTip!
Advisories are also available from the
GraphQL API