GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
142 advisories
Filter by severity
Twig has a possible sandbox bypass
Moderate
CVE-2024-45411
was published
for
twig/twig
(Composer)
Sep 9, 2024
Windows Mark of the Web Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-38217
was published
Sep 10, 2024
Windows Mark of the Web Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-43487
was published
Sep 10, 2024
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing...
Moderate
Unreviewed
CVE-2024-45833
was published
Sep 16, 2024
@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection
Moderate
CVE-2024-46976
was published
for
@backstage/plugin-techdocs-backend
(npm)
Sep 17, 2024
A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low...
Moderate
Unreviewed
CVE-2024-20438
was published
Oct 2, 2024
BitLocker Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-43513
was published
Oct 8, 2024
Code Integrity Guard Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-43585
was published
Oct 8, 2024
Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi...
Moderate
Unreviewed
CVE-2023-32644
was published
Oct 29, 2024
Windows Package Library Manager Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-38203
was published
Nov 12, 2024
Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-43645
was published
Nov 12, 2024
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could...
Moderate
Unreviewed
CVE-2021-1494
was published
Nov 15, 2024
Jinja has a sandbox breakout through indirect reference to format method
Moderate
CVE-2024-56326
was published
for
jinja2
(pip)
Dec 23, 2024
Denial of Service in Keycloak Server via Security Headers
Moderate
CVE-2024-11734
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
Secure Boot Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2025-21211
was published
Jan 14, 2025
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login...
Moderate
Unreviewed
CVE-2024-13794
was published
Feb 12, 2025
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a...
Moderate
Unreviewed
CVE-2025-26637
was published
Apr 8, 2025
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to...
Moderate
Unreviewed
CVE-2025-27472
was published
Apr 8, 2025
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries
Moderate
GHSA-pmc3-p9hx-jq96
was published
for
github.com/refraction-networking/utls
(Go)
Apr 23, 2025
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a...
Moderate
Unreviewed
CVE-2025-47160
was published
Jun 10, 2025
The application fails to implement several security headers. These headers help increase the...
Moderate
Unreviewed
CVE-2025-49193
was published
Jun 12, 2025
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a...
Moderate
Unreviewed
CVE-2025-48003
was published
Jul 8, 2025
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a...
Moderate
Unreviewed
CVE-2025-48800
was published
Jul 8, 2025
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks...
Moderate
Unreviewed
CVE-2025-52951
was published
Jul 11, 2025
ProTip!
Advisories are also available from the
GraphQL API