GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,782
Erlang
36
GitHub Actions
29
Go
2,347
Maven
5,000+
npm
3,976
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,638 advisories
Filter by severity
A vulnerability has been found in Netgear DGND3700 1.1.00.15_1.00.15NA and classified as...
Moderate
Unreviewed
CVE-2025-4980
was published
May 20, 2025
Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read...
Moderate
Unreviewed
CVE-2024-54188
was published
May 22, 2025
PrinterShare Android application allows the capture of Gmail authentication tokens that can be...
Critical
Unreviewed
CVE-2025-5098
was published
May 23, 2025
An unauthenticated remote attacker can access information about running processes via the SNMP...
High
Unreviewed
CVE-2025-41654
was published
May 26, 2025
A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1....
Moderate
Unreviewed
CVE-2025-5184
was published
May 26, 2025
Script elements loading cross-origin resources generated load and error events which leaked...
Moderate
Unreviewed
CVE-2025-5266
was published
May 27, 2025
There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This...
Moderate
Unreviewed
CVE-2024-56193
was published
May 27, 2025
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55...
Moderate
Unreviewed
CVE-2025-5064
was published
May 27, 2025
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote...
Moderate
Unreviewed
CVE-2025-5281
was published
May 27, 2025
Exposure of private personal information to an unauthorized actor in the user vaults component of...
High
Unreviewed
CVE-2025-5334
was published
May 29, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-31231
was published
May 30, 2025
The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms...
Moderate
Unreviewed
CVE-2025-4659
was published
May 30, 2025
A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic....
Moderate
Unreviewed
CVE-2025-5436
was published
Jun 2, 2025
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP),...
Moderate
Unreviewed
CVE-2025-20129
was published
Jun 4, 2025
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass...
Moderate
Unreviewed
CVE-2025-5690
was published
Jun 5, 2025
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
Exposure of sensitive information to an unauthorized actor in Power Automate allows an...
Critical
Unreviewed
CVE-2025-47966
was published
Jun 5, 2025
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes,...
Moderate
Unreviewed
CVE-2025-25209
was published
Jun 9, 2025
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
High
CVE-2025-49653
was published
for
backend.ai
(pip)
Jun 9, 2025
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an...
Moderate
Unreviewed
CVE-2025-40662
was published
Jun 10, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
GWC Home Page communicate version and revision information
Moderate
CVE-2024-38524
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS...
Moderate
Unreviewed
CVE-2025-25250
was published
Jun 10, 2025
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized...
Moderate
Unreviewed
CVE-2025-47969
was published
Jun 10, 2025
Nautobot may allows uploaded media files to be accessible without authentication
Moderate
CVE-2025-49143
was published
for
nautobot
(pip)
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API