GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,783
Erlang
36
GitHub Actions
29
Go
2,353
Maven
5,000+
npm
3,977
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,643 advisories
Filter by severity
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an...
Moderate
Unreviewed
CVE-2025-43579
was published
Jun 10, 2025
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the...
High
Unreviewed
CVE-2025-26521
was published
Jun 11, 2025
In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A...
Moderate
Unreviewed
CVE-2025-30675
was published
Jun 11, 2025
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions...
Moderate
Unreviewed
CVE-2025-4798
was published
Jun 11, 2025
A remote unauthorized attacker may gather sensitive information of the application, due to...
High
Unreviewed
CVE-2025-49184
was published
Jun 12, 2025
The created backup files are unencrypted, making the application vulnerable for gathering...
Moderate
Unreviewed
CVE-2025-49200
was published
Jun 12, 2025
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not...
Moderate
Unreviewed
CVE-2025-49177
was published
Jun 17, 2025
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is...
Low
Unreviewed
CVE-2025-6199
was published
Jun 17, 2025
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual...
High
Unreviewed
CVE-2025-23173
was published
Jun 19, 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions...
Critical
Unreviewed
CVE-2025-25037
was published
Jun 20, 2025
An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to...
Moderate
Unreviewed
CVE-2023-47298
was published
Jun 23, 2025
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and...
Critical
Unreviewed
CVE-2023-47029
was published
Jun 23, 2025
OPPO Clone Phone uses a weak password WiFi hotspot to transfer files, resulting in Information...
High
Unreviewed
CVE-2025-27387
was published
Jun 23, 2025
A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering...
High
Unreviewed
CVE-2025-39204
was published
Jun 24, 2025
An attacker who enumerated resources from the WebCompat extension could have obtained a...
Moderate
Unreviewed
CVE-2025-6425
was published
Jun 26, 2025
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when...
High
Unreviewed
CVE-2025-6432
was published
Jun 26, 2025
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.2.0.3...
High
Unreviewed
CVE-2025-27827
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API