GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,026
Maven
5,000+
npm
4,763
NuGet
824
pip
4,366
Pub
12
RubyGems
987
Rust
1,143
Swift
50
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
69 advisories
Filter by severity
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure...
High
Unreviewed
CVE-2025-68460
was published
Dec 18, 2025
GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18...
High
Unreviewed
CVE-2025-8405
was published
Dec 11, 2025
A vulnerability exists in PX Enterprise whereby sensitive information may be logged under...
High
Unreviewed
CVE-2025-9127
was published
Dec 4, 2025
A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This...
High
Unreviewed
CVE-2025-11085
was published
Nov 11, 2025
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into...
High
Unreviewed
CVE-2025-11713
was published
Oct 14, 2025
A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize...
High
Unreviewed
CVE-2025-55903
was published
Oct 10, 2025
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
High
Unreviewed
CVE-2021-25254
was published
May 21, 2025
A vulnerability exists in PX Backup whereby sensitive information may be logged under specific...
High
Unreviewed
CVE-2025-1308
was published
May 20, 2025
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows...
High
Unreviewed
CVE-2025-24338
was published
Apr 30, 2025
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0...
High
Unreviewed
CVE-2024-12368
was published
Feb 25, 2025
A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3...
High
Unreviewed
CVE-2024-46547
was published
Dec 9, 2024
In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper...
High
Unreviewed
CVE-2018-9433
was published
Nov 20, 2024
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow...
High
Unreviewed
CVE-2024-47549
was published
Oct 25, 2024
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
High
Unreviewed
CVE-2024-9348
was published
Oct 16, 2024
Account users in Apache CloudStack by default are allowed to upload and register templates for...
High
Unreviewed
CVE-2024-45219
was published
Oct 16, 2024
An unauthenticated local attacker can gain admin privileges by deploying a config file due to...
High
Unreviewed
CVE-2024-45271
was published
Oct 15, 2024
In shouldRestrictOverlayActivities of UsbProfileGroupSettingsManager.java, there is a possible...
High
Unreviewed
CVE-2024-34739
was published
Aug 16, 2024
Windows App Installer Spoofing Vulnerability
High
Unreviewed
CVE-2024-38177
was published
Aug 13, 2024
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with...
High
Unreviewed
CVE-2024-38473
was published
Jul 1, 2024
An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via...
High
Unreviewed
CVE-2024-27629
was published
Jun 29, 2024
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server...
High
Unreviewed
CVE-2024-4177
was published
Jun 6, 2024
A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a...
High
Unreviewed
CVE-2024-1064
was published
Feb 3, 2024
Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a...
High
Unreviewed
CVE-2023-28738
was published
Jan 19, 2024
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this...
High
Unreviewed
CVE-2023-52102
was published
Jan 16, 2024
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this...
High
Unreviewed
CVE-2023-52098
was published
Jan 16, 2024
ProTip!
Advisories are also available from the
GraphQL API