GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
71 advisories
Filter by severity
In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer...
Moderate
Unreviewed
CVE-2025-59820
was published
Nov 26, 2025
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/ops-common: ignore...
Moderate
Unreviewed
CVE-2025-39700
was published
Sep 5, 2025
Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on...
Moderate
Unreviewed
CVE-2025-10259
was published
Nov 6, 2025
In the Linux kernel, the following vulnerability has been resolved:
ext4: avoid resizing to a...
Moderate
Unreviewed
CVE-2022-50020
was published
Jun 18, 2025
N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N...
Moderate
Unreviewed
CVE-2025-9316
was published
Nov 12, 2025
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site...
Moderate
Unreviewed
CVE-2022-31629
was published
Sep 29, 2022
In the Linux kernel, the following vulnerability has been resolved:
netdevsim: prevent bad user...
Moderate
Unreviewed
CVE-2024-56716
was published
Dec 29, 2024
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated...
Moderate
Unreviewed
CVE-2025-36092
was published
Nov 3, 2025
A data corruption vulnerability has been identified in the luksmeta utility when used with the...
Moderate
Unreviewed
CVE-2025-11568
was published
Oct 15, 2025
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric...
Moderate
Unreviewed
CVE-2025-3511
was published
Apr 25, 2025
In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime...
Moderate
Unreviewed
CVE-2025-0038
was published
Oct 6, 2025
A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows...
Moderate
Unreviewed
CVE-2024-6768
was published
Aug 12, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2...
Moderate
Unreviewed
CVE-2025-10094
was published
Sep 12, 2025
Improper Input Validation vulnerability in ABB 800xA Base.
An attacker who successfully exploited...
Moderate
Unreviewed
CVE-2024-3036
was published
Jun 21, 2024
Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged...
Moderate
Unreviewed
CVE-2024-36346
was published
Sep 6, 2025
Improper Validation of Specified Quantity in Input vulnerability in calliko Bonus for Woo allows...
Moderate
Unreviewed
CVE-2025-58835
was published
Sep 5, 2025
The Eaton Foreseer software provides multiple customizable input fields for the users to...
Moderate
Unreviewed
CVE-2024-31416
was published
Sep 13, 2024
Arbitrary file read in NetScaler Console and NetScaler SDX (SVM)
Moderate
Unreviewed
CVE-2025-4365
was published
Jun 17, 2025
A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3...
Moderate
Unreviewed
CVE-2025-20151
was published
May 7, 2025
Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System...
Moderate
Unreviewed
CVE-2025-43881
was published
Jul 23, 2025
Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible...
Moderate
Unreviewed
CVE-2025-41100
was published
Jul 21, 2025
Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder...
Moderate
Unreviewed
CVE-2025-49292
was published
Jun 6, 2025
An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an...
Moderate
Unreviewed
CVE-2025-32399
was published
May 7, 2025
A lack of length validation in Snippet descriptions in GitLab CE/EE affecting all versions prior...
Moderate
Unreviewed
CVE-2022-2592
was published
Oct 17, 2022
In findAllDeAccounts of AccountsDb.java, there is a possible denial of service due to resource...
Moderate
Unreviewed
CVE-2021-0934
was published
Dec 13, 2022
ProTip!
Advisories are also available from the
GraphQL API