GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,809
Erlang
36
GitHub Actions
31
Go
2,393
Maven
5,000+
npm
4,026
NuGet
720
pip
3,818
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
12,203 advisories
Filter by severity
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high...
Low
Unreviewed
CVE-2025-42954
was published
Jul 8, 2025
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Low
CVE-2025-53535
was published
for
better-auth
(npm)
Jul 7, 2025
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform...
Low
Unreviewed
CVE-2025-20325
was published
Jul 7, 2025
Transformers's Improper Input Validation vulnerability can be exploited through username injection
Low
CVE-2025-3777
was published
for
transformers
(pip)
Jul 7, 2025
Stack overflow risk when vector images are parsed during file preview
Impact: Successful...
Low
Unreviewed
CVE-2025-53176
was published
Jul 7, 2025
Permission bypass vulnerability in the calendar storage module
Impact: Successful exploitation of...
Low
Unreviewed
CVE-2025-53177
was published
Jul 7, 2025
A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This...
Low
Unreviewed
CVE-2025-7060
was published
Jul 4, 2025
Next.js has a Cache poisoning vulnerability due to omission of the Vary header
Low
CVE-2025-49005
was published
for
next
(npm)
Jul 3, 2025
Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2025-0885
was published
Jul 3, 2025
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that...
Low
Unreviewed
CVE-2025-6943
was published
Jul 2, 2025
The distributed engine of Secret Server versions 11.7.49 and earlier can be exploited during an...
Low
Unreviewed
CVE-2025-6942
was published
Jul 2, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-53492
was published
Jul 2, 2025
Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message...
Low
Unreviewed
CVE-2025-24335
was published
Jul 2, 2025
The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the...
Low
Unreviewed
CVE-2025-24334
was published
Jul 2, 2025
Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and...
Low
Unreviewed
CVE-2025-52463
was published
Jul 2, 2025
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of...
Low
Unreviewed
CVE-2025-4654
was published
Jul 2, 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the...
Low
Unreviewed
CVE-2025-32462
was published
Jun 30, 2025
string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)
Low
CVE-2025-45143
was published
for
string-math
(npm)
Jun 30, 2025
File Browser's password protection of links is bypassable
Low
CVE-2025-52996
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce...
Low
Unreviewed
CVE-2025-40710
was published
Jun 30, 2025
RLPx 5 has two CTR streams based on the same key, IV, and nonce. This can facilitate decryption...
Low
Unreviewed
CVE-2015-20112
was published
Jun 29, 2025
An integer overflow in the image processing binary of the MIB3 infotainment unit allows an...
Low
Unreviewed
CVE-2023-28903
was published
Jun 28, 2025
An integer underflow in the image processing binary of the MIB3 infotainment unit allows an...
Low
Unreviewed
CVE-2023-28902
was published
Jun 28, 2025
Taylor has race condition in /get-patch that allows purchase token replay
Low
GHSA-vh5j-5fhq-9xwg
was published
for
taylored
(npm)
Jun 27, 2025
The Nix, Lix, and Guix package managers default to using temporary build directories in a world...
Low
Unreviewed
CVE-2025-52991
was published
Jun 27, 2025
ProTip!
Advisories are also available from the
GraphQL API