GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,094 advisories
Filter by severity
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This...
Moderate
Unreviewed
CVE-2025-53075
was published
Jun 30, 2025
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers...
Moderate
Unreviewed
CVE-2025-53076
was published
Jun 30, 2025
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue...
Moderate
Unreviewed
CVE-2025-5878
was published
Jun 29, 2025
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results...
Moderate
Unreviewed
CVE-2023-28911
was published
Jun 28, 2025
ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This...
Moderate
Unreviewed
CVE-2025-6444
was published
Jun 26, 2025
A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version...
Moderate
Unreviewed
CVE-2025-34032
was published
Jun 26, 2025
Denied Host Validation Bypass in Zitadel Actions
Moderate
CVE-2024-49753
was published
for
github.com/zitadel/zitadel
(Go)
Oct 25, 2024
In video decoder, there is a possible improper input validation. This could lead to local denial...
Moderate
Unreviewed
CVE-2023-48346
was published
Jan 18, 2024
In telephone service, there is a possible improper input validation. This could lead to local...
Moderate
Unreviewed
CVE-2023-48354
was published
Jan 18, 2024
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This...
Moderate
Unreviewed
CVE-2025-6279
was published
Jun 19, 2025
Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path...
Moderate
Unreviewed
CVE-2025-6240
was published
Jun 18, 2025
There is an insufficient input validation vulnerability in the warehouse
component of Absolute...
Moderate
Unreviewed
CVE-2025-49081
was published
Jun 12, 2025
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been declared as...
Moderate
Unreviewed
CVE-2025-5497
was published
Jun 3, 2025
A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic....
Moderate
Unreviewed
CVE-2025-4905
was published
May 19, 2025
Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page
Moderate
CVE-2024-45478
was published
for
org.apache.ranger:ranger
(Maven)
Jan 22, 2025
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute...
Moderate
Unreviewed
CVE-2025-47171
was published
Jun 10, 2025
In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime...
Moderate
Unreviewed
CVE-2025-0037
was published
Jun 10, 2025
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x...
Moderate
Unreviewed
CVE-2022-42012
was published
Oct 10, 2022
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
Moderate
Unreviewed
CVE-2025-27131
was published
Jun 8, 2025
HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-5173
was published
for
label-studio-ml
(pip)
May 26, 2025
Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a...
Moderate
Unreviewed
CVE-2024-22027
was published
Jan 12, 2024
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information...
Moderate
Unreviewed
CVE-2025-5680
was published
Jun 5, 2025
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information...
Moderate
Unreviewed
CVE-2025-5679
was published
Jun 5, 2025
pypickle unsafe deserialization vulnerability
Moderate
CVE-2025-5174
was published
for
pypickle
(pip)
May 26, 2025
Laravel Rest Api has a Search Validation Bypass
Moderate
CVE-2025-48490
was published
for
lomkit/laravel-rest-api
(Composer)
May 27, 2025
ProTip!
Advisories are also available from the
GraphQL API