GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            23 advisories
        Filter by severity
        
      
      
    
                    
                      The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59447
                      
                      was published
                      Oct 6, 2025 
                    
                  
                    
                      Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58866
                      
                      was published
                      Sep 5, 2025 
                    
                  
                    
                      IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2667
                      
                      was published
                      Sep 4, 2025 
                    
                  
                    
                      IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2988
                      
                      was published
                      Aug 19, 2025 
                    
                  
                    
                      NVIDIA GPU Display Driver for Windows contains a vulnerability  where an attacker may cause an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-23288
                      
                      was published
                      Aug 3, 2025 
                    
                  
                    
                      NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-23287
                      
                      was published
                      Aug 3, 2025 
                    
                  
                    
                      A flaw was found in Ansible. Three API endpoints are accessible and return verbose,...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53862
                      
                      was published
                      Jul 11, 2025 
                    
                  
                    
                      The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-24334
                      
                      was published
                      Jul 2, 2025 
                    
                  
                    
                      A vulnerability has been identified in Keycloak that could lead to unauthorized information...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5416
                      
                      was published
                      Jun 20, 2025 
                    
                  
                    
                      In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-0036
                      
                      was published
                      Jun 10, 2025 
                    
                  
                    
                      A exposure of sensitive system information to an unauthorized control sphere in Fortinet...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-24473
                      
                      was published
                      May 28, 2025 
                    
                  
                    
                      Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2236
                      
                      was published
                      May 27, 2025 
                    
                  
                    
                      sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
                    
                      
  Low
                    
                
                      
                        CVE-2025-46718
                      
                      was published
                        for
                        
                          sudo-rs
                        
                        (Rust)
                      May 13, 2025 
                    
                  
                    
                      sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
                    
                      
  Low
                    
                
                      
                        CVE-2025-46717
                      
                      was published
                        for
                        
                          sudo-rs
                        
                        (Rust)
                      May 13, 2025 
                    
                  
                    
                      Mattermost doesn't restrict domains LLM can request to contact upstream
                    
                      
  Low
                    
                
                      
                        CVE-2025-31363
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost/server/v8
                        
                        (Go)
                      Apr 16, 2025 
                    
                  
                    
                      Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-31003
                      
                      was published
                      Apr 9, 2025 
                    
                  
                    
                      In getCustomPrinterIcon of PrintManagerService.java, there is a possible way to view other user's...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-0053
                      
                      was published
                      Mar 11, 2024 
                    
                  
                    
                      IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-52905
                      
                      was published
                      Mar 10, 2025 
                    
                  
                    
                      Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-11035
                      
                      was published
                      Mar 5, 2025 
                    
                  
                    
                      IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-23472
                      
                      was published
                      Dec 11, 2024 
                    
                  
                    
                      Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-47799
                      
                      was published
                      Nov 12, 2024 
                    
                  
                    
                      An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-5081
                      
                      was published
                      Jan 19, 2024 
                    
                  
                    
                      IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-42010
                      
                      was published
                      Jul 17, 2024 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API