GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
89 advisories
Filter by severity
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an...
High
Unreviewed
CVE-2025-3875
was published
May 14, 2025
An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP...
High
Unreviewed
CVE-2025-28128
was published
Apr 25, 2025
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in...
High
Unreviewed
CVE-2025-29621
was published
Apr 22, 2025
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this...
High
Unreviewed
CVE-2025-2188
was published
Apr 17, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2025-31170
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58126
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58127
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58125
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58124
was published
Apr 7, 2025
A crafted URL containing specific Unicode characters could have hidden the true origin of the...
High
Unreviewed
CVE-2025-3029
was published
Apr 1, 2025
An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur....
High
Unreviewed
CVE-2025-30142
was published
Mar 18, 2025
Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which...
High
Unreviewed
CVE-2025-26696
was published
Mar 10, 2025
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and...
High
Unreviewed
CVE-2025-24458
was published
Jan 21, 2025
Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested....
High
Unreviewed
CVE-2024-50380
was published
Dec 2, 2024
A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them...
High
Unreviewed
CVE-2024-36466
was published
Nov 28, 2024
CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of...
High
Unreviewed
CVE-2024-8935
was published
Nov 13, 2024
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This...
High
Unreviewed
CVE-2024-10462
was published
Oct 29, 2024
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This...
High
Unreviewed
CVE-2024-10465
was published
Oct 29, 2024
Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing,...
High
Unreviewed
CVE-2024-49193
was published
Oct 12, 2024
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the...
High
Unreviewed
CVE-2024-44104
was published
Sep 10, 2024
The CloudStack SAML authentication (disabled by default) does not enforce signature check. In...
High
Unreviewed
CVE-2024-41107
was published
Jul 19, 2024
PingOne MFA Integration Kit contains a vulnerability where the skipMFA action can be configured...
High
Unreviewed
CVE-2023-40702
was published
Jul 9, 2024
PingOne MFA Integration Kit contains a vulnerability related to the Prompt Users to Set Up MFA...
High
Unreviewed
CVE-2023-40356
was published
Jul 9, 2024
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can...
High
Unreviewed
CVE-2024-5037
was published
Jun 5, 2024
cdbattags lua-resty-jwt 0.2.3 allows attackers to bypass all JWT-parsing signature checks by...
High
Unreviewed
CVE-2024-33531
was published
Apr 24, 2024
ProTip!
Advisories are also available from the
GraphQL API