GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
87 advisories
Filter by severity
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
Low
GHSA-rcmh-qjqh-p98v
was published
for
nodemailer
(npm)
Dec 1, 2025
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This...
Critical
Unreviewed
CVE-2025-13023
was published
Nov 11, 2025
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This...
Critical
Unreviewed
CVE-2025-13026
was published
Nov 11, 2025
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects...
Critical
Unreviewed
CVE-2025-13021
was published
Nov 11, 2025
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects...
Critical
Unreviewed
CVE-2025-13022
was published
Nov 11, 2025
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability...
High
Unreviewed
CVE-2025-13016
was published
Nov 11, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
Under undisclosed traffic conditions along with conditions beyond the attacker's control,...
High
Unreviewed
CVE-2025-58153
was published
Oct 15, 2025
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore...
Moderate
Unreviewed
CVE-2025-11594
was published
Oct 11, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
High
CVE-2025-59538
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
High
CVE-2025-59531
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
TinyEnv: Missing .env file not required — may cause unexpected behavior
Moderate
CVE-2025-58758
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
In Permission Manager, there is a possible way for the microphone privacy indicator to remain...
Low
Unreviewed
CVE-2025-26461
was published
Sep 5, 2025
In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server...
Moderate
Unreviewed
CVE-2025-26456
was published
Sep 5, 2025
In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic...
Moderate
Unreviewed
CVE-2025-22413
was published
Aug 27, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. A...
Moderate
Unreviewed
CVE-2025-43240
was published
Jul 30, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6....
Moderate
Unreviewed
CVE-2025-24188
was published
Jul 30, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It...
High
Unreviewed
CVE-2024-47215
was published
Apr 3, 2025
When run on commands with certain arguments set, explain may fail to validate these arguments...
Moderate
Unreviewed
CVE-2025-3084
was published
Apr 1, 2025
ntpd NTS client denial of service via wrongly sized cookies
Moderate
GHSA-v83q-83hj-rw38
was published
for
ntpd
(Rust)
Feb 28, 2025
CometBFT allows a malicious peer to make node stuck in blocksync
Moderate
CVE-2025-24371
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a...
High
Unreviewed
CVE-2024-50954
was published
Jan 15, 2025
Lodestar snappy decompression issue
Low
GHSA-53rv-hcvm-rpp9
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
Vyper Does Not Check the Success of Certain Precompile Calls
Low
CVE-2025-21607
was published
for
vyper
(pip)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API