GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            41 advisories
        Filter by severity
        
      
      
    
                    
                      Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
                    
                      
  Critical
                    
                
                      
                        GHSA-hf6h-9wq7-hmjg
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Picklescan Bypass is Possible via File Extension Mismatch
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10155
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 10, 2025 
                    
                  
                    
                      Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10156
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 10, 2025 
                    
                  
                    
                      Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10157
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 10, 2025 
                    
                  
                    
                      The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59033
                      
                      was published
                      Sep 8, 2025 
                    
                  
                    
                      Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43728
                      
                      was published
                      Aug 27, 2025 
                    
                  
                    
                      Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54143
                      
                      was published
                      Aug 19, 2025 
                    
                  
                    
                      A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6,...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43261
                      
                      was published
                      Jul 30, 2025 
                    
                  
                    
                      A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43273
                      
                      was published
                      Jul 30, 2025 
                    
                  
                    
                      An attacker was able to bypass the `connect-src` directive of a Content Security Policy by...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6427
                      
                      was published
                      Jun 26, 2025 
                    
                  
                    
                      Spring Security authorization bypass for method security annotations on private methods
                    
                      
  Critical
                    
                
                      
                        CVE-2025-41232
                      
                      was published
                        for
                        
                          org.springframework.security:spring-security-aspects
                        
                        (Maven)
                      May 21, 2025 
                    
                  
                    
                      Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27665
                      
                      was published
                      Mar 5, 2025 
                    
                  
                    
                      Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-25091
                      
                      was published
                      Mar 1, 2024 
                    
                  
                    
                      Vulnerability of incorrect service logic in the WindowManagerServices module.Successful...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-52378
                      
                      was published
                      Feb 18, 2024 
                    
                  
                    
                      Protection mechanism failure in some Intel DCM software before version 5.2 may allow an...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-31273
                      
                      was published
                      Nov 14, 2023 
                    
                  
                    
                      
Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-32493
                      
                      was published
                      Aug 16, 2023 
                    
                  
                    
                      Microsoft Office Security Feature Bypass Vulnerability
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-33150
                      
                      was published
                      Jul 11, 2023 
                    
                  
                    
                      Sandbox escape in Jenkins Email Extension Plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2023-25765
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:email-ext
                        
                        (Maven)
                      Feb 15, 2023 
                    
                  
                    
                      The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-48290
                      
                      was published
                      Feb 9, 2023 
                    
                  
                    
                      An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-47544
                      
                      was published
                      Jan 5, 2023 
                    
                  
                    
                      If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code>...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-26384
                      
                      was published
                      Dec 22, 2022 
                    
                  
                    
                      If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-22759
                      
                      was published
                      Dec 22, 2022 
                    
                  
                    
                      User login brute force protection functionality bypass
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-27516
                      
                      was published
                      Nov 9, 2022 
                    
                  
                    
                      Jenkins Script Security Plugin sandbox bypass vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2022-43403
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:script-security
                        
                        (Maven)
                      Oct 19, 2022 
                    
                  
                    
                      Jenkins Pipeline: Groovy Plugin allows sandbox protection bypass and arbitrary code execution
                    
                      
  Critical
                    
                
                      
                        CVE-2022-43402
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins.workflow:workflow-cps
                        
                        (Maven)
                      Oct 19, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API