GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
54 advisories
Filter by severity
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for...
High
Unreviewed
CVE-2021-39364
was published
Feb 25, 2022
Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric...
High
Unreviewed
CVE-2022-25155
was published
Apr 3, 2022
Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series...
High
Unreviewed
CVE-2022-25159
was published
Apr 3, 2022
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to...
High
Unreviewed
CVE-2020-27374
was published
Apr 8, 2022
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange...
High
Unreviewed
CVE-2002-0054
was published
Apr 30, 2022
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are...
High
Unreviewed
CVE-2018-17935
was published
May 13, 2022
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode...
High
Unreviewed
CVE-2018-17176
was published
May 13, 2022
Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100)...
High
Unreviewed
CVE-2019-3915
was published
May 13, 2022
All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence...
High
Unreviewed
CVE-2018-7356
was published
May 13, 2022
Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to...
High
Unreviewed
CVE-2017-11786
was published
May 13, 2022
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level...
High
Unreviewed
CVE-2017-6823
was published
May 13, 2022
YSoft SafeQ Server 6 allows a replay attack.
High
Unreviewed
CVE-2018-15498
was published
May 13, 2022
A vulnerability has been identified in SICAM P850 (All versions < V3.00), SICAM P850 (All...
High
Unreviewed
CVE-2022-29878
was published
May 21, 2022
Netwrix Account Lockout Examiner before 5.1 allows remote attackers to capture the Net-NTLMv1/v2...
High
Unreviewed
CVE-2020-15931
was published
May 24, 2022
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2...
High
Unreviewed
CVE-2020-25660
was published
May 24, 2022
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3)....
High
Unreviewed
CVE-2020-25229
was published
May 24, 2022
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur...
High
Unreviewed
CVE-2021-27572
was published
May 24, 2022
Windows NTLM Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2021-31958
was published
May 24, 2022
The KT-1 door controller is susceptible to replay or man-in-the-middle attacks where an attacker...
High
Unreviewed
CVE-2021-27662
was published
May 24, 2022
A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem...
High
Unreviewed
CVE-2021-25480
was published
May 24, 2022
Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g...
High
Unreviewed
CVE-2021-35067
was published
May 24, 2022
The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to...
High
Unreviewed
CVE-2022-31265
was published
May 27, 2022
Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows...
High
Unreviewed
CVE-2022-31277
was published
Jun 17, 2022
Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all...
High
Unreviewed
CVE-2022-34151
was published
Jul 5, 2022
Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ...
High
Unreviewed
CVE-2022-33208
was published
Jul 5, 2022
ProTip!
Advisories are also available from the
GraphQL API