GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            178 advisories
        Filter by severity
        
      
      
    
                    
                      A data corruption vulnerability has been identified in the luksmeta utility when used with the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11568
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61938
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-0038
                      
                      was published
                      Oct 6, 2025 
                    
                  
                    
                      Liferay Portal has Improper Validation of Specified Quantity in Input
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43793
                      
                      was published
                        for
                        
                          com.liferay.portal:com.liferay.portal.impl
                        
                        (Maven)
                      Sep 15, 2025 
                    
                  
                    
                      An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2256
                      
                      was published
                      Sep 12, 2025 
                    
                  
                    
                      An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10094
                      
                      was published
                      Sep 12, 2025 
                    
                  
                    
                      Improper Validation of Specified Quantity in Input vulnerability in ThemesGrove WP SmartPay. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-32689
                      
                      was published
                      Sep 9, 2025 
                    
                  
                    
                      Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-36346
                      
                      was published
                      Sep 6, 2025 
                    
                  
                    
                      Improper Validation of Specified Quantity in Input vulnerability in calliko Bonus for Woo allows...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58835
                      
                      was published
                      Sep 5, 2025 
                    
                  
                    
                      Improper Input Validation vulnerability in OpenText Self Service Password Reset allows...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5808
                      
                      was published
                      Aug 29, 2025 
                    
                  
                    
                      Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8424
                      
                      was published
                      Aug 26, 2025 
                    
                  
                    
                      An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55398
                      
                      was published
                      Aug 22, 2025 
                    
                  
                    
                      Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8320
                      
                      was published
                      Jul 30, 2025 
                    
                  
                    
                      Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43881
                      
                      was published
                      Jul 23, 2025 
                    
                  
                    
                      Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-41100
                      
                      was published
                      Jul 21, 2025 
                    
                  
                    
                      resolv vulnerable to DoS via insufficient DNS domain name length validation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-24294
                      
                      was published
                        for
                        
                          resolv
                        
                        (RubyGems)
                      Jul 15, 2025 
                    
                  
                    
                      Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4365
                      
                      was published
                      Jun 17, 2025 
                    
                  
                    
                      Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5349
                      
                      was published
                      Jun 17, 2025 
                    
                  
                    
                      Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-49292
                      
                      was published
                      Jun 6, 2025 
                    
                  
                    
                      Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-5257
                      
                      was published
                        for
                        
                          mautic/core
                        
                        (Composer)
                      May 28, 2025 
                    
                  
                    
                      n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2826
                      
                      was published
                      May 28, 2025 
                    
                  
                    
                      On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-9448
                      
                      was published
                      May 8, 2025 
                    
                  
                    
                      A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-20151
                      
                      was published
                      May 7, 2025 
                    
                  
                    
                      An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-32399
                      
                      was published
                      May 7, 2025 
                    
                  
                    
                      markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
                    
                      
  Low
                    
                
                      
                        CVE-2025-46656
                      
                      was published
                        for
                        
                          markdownify
                        
                        (pip)
                      Apr 27, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API