GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
40 advisories
Filter by severity
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2021-20450
was published
May 3, 2024
Client-side enforcement of server-side security issue exists in WL-WN531AX2 firmware versions...
High
Unreviewed
CVE-2023-32612
was published
Jun 30, 2023
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an...
Moderate
Unreviewed
CVE-2024-1551
was published
Feb 20, 2024
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password,...
Critical
Unreviewed
CVE-2024-28288
was published
Mar 30, 2024
The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass...
Moderate
Unreviewed
CVE-2024-9820
was published
Oct 15, 2024
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote...
High
Unreviewed
CVE-2024-9970
was published
Oct 15, 2024
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2024-39734
was published
Jul 14, 2024
Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics...
Critical
Unreviewed
CVE-2024-0947
was published
Jun 27, 2024
The device allows an unauthenticated attacker to bypass authentication
and modify the cookie to...
High
Unreviewed
CVE-2024-21872
was published
Apr 19, 2024
The application suffers from a privilege escalation vulnerability. An
attacker logged in as...
High
Unreviewed
CVE-2024-22186
was published
Apr 19, 2024
The website configured in the URL widget will receive a session cookie when testing or executing...
High
Unreviewed
CVE-2023-32725
was published
Dec 22, 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
Critical
Unreviewed
CVE-2023-35885
was published
Jun 20, 2023
Reliance on Cookies without Validation and Integrity Checking in a Security Decision...
Critical
Unreviewed
CVE-2023-3050
was published
Jun 13, 2023
** UNSUPPPORTED WHEN ASSIGNED **
Session management within the web application is...
Critical
Unreviewed
CVE-2023-41084
was published
Sep 18, 2023
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain...
High
Unreviewed
CVE-2008-5784
was published
May 17, 2022
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware...
High
Unreviewed
CVE-2021-33842
was published
May 24, 2022
All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without...
Moderate
Unreviewed
CVE-2022-3083
was published
Feb 1, 2023
WAGO 750-8212 PFC200 G2 2ETH RS Firmware version 03.05.10(17) is affected by a privilege...
High
Unreviewed
CVE-2021-46388
was published
Feb 17, 2022
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
Critical
Unreviewed
CVE-2022-38297
was published
Sep 13, 2022
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access...
Critical
Unreviewed
CVE-2018-5190
was published
May 13, 2022
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1...
Critical
Unreviewed
CVE-2018-20512
was published
May 13, 2022
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0,...
Moderate
Unreviewed
CVE-2017-8034
was published
May 13, 2022
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an...
High
Unreviewed
CVE-2017-6896
was published
May 13, 2022
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to...
Critical
Unreviewed
CVE-2017-7279
was published
May 13, 2022
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability....
High
Unreviewed
CVE-2021-36338
was published
Jan 22, 2022
ProTip!
Advisories are also available from the
GraphQL API