GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,582 advisories
Filter by severity
An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10871
was published
Sep 26, 2025
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
Low
CVE-2025-1396
was published
for
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt
(Maven)
Sep 26, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10867
was published
Sep 26, 2025
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for...
Low
Unreviewed
CVE-2025-10173
was published
Sep 26, 2025
A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the...
Low
Unreviewed
CVE-2025-10977
was published
Sep 26, 2025
A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown...
Low
Unreviewed
CVE-2025-10976
was published
Sep 26, 2025
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation...
Low
Unreviewed
CVE-2025-60019
was published
Sep 25, 2025
Ericsson
Indoor Connect 8855 contains a vulnerability where server-side security can be
bypassed...
Low
Unreviewed
CVE-2025-40838
was published
Sep 25, 2025
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in...
Low
Unreviewed
CVE-2025-5494
was published
Sep 25, 2025
Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in...
Low
Unreviewed
CVE-2025-36857
was published
Sep 25, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
web3-core-subscriptions has a Prototype Pollution vulnerability
Low
CVE-2025-57330
was published
for
web3-core-subscriptions
(npm)
Sep 24, 2025
web3-core-method is vulnerable to prototype pollution
Low
CVE-2025-57329
was published
for
web3-core-method
(npm)
Sep 24, 2025
magix-combine-ex vulnerable to prototype pollution
Low
CVE-2025-57321
was published
for
magix-combine-ex
(npm)
Sep 24, 2025
node-cube vulnerable to prototype pollution
Low
CVE-2025-57348
was published
for
node-cube
(npm)
Sep 24, 2025
messageformat has a prototype pollution vulnerability
Low
CVE-2025-57349
was published
for
messageformat
(npm)
Sep 24, 2025
rollbar vulnerable to prototype pollution
Low
CVE-2025-57325
was published
for
rollbar
(npm)
Sep 24, 2025
sassdoc-extras vulnerable to prototype pollution
Low
CVE-2025-57326
was published
for
sassdoc-extras
(npm)
Sep 24, 2025
spmrc vulnerable to prototype pollution
Low
CVE-2025-57327
was published
for
spmrc
(npm)
Sep 24, 2025
toggle-array vulnerable to prototype pollution
Low
CVE-2025-57328
was published
for
toggle-array
(npm)
Sep 24, 2025
fast-redact vulnerable to prototype pollution
Low
CVE-2025-57319
was published
for
fast-redact
(npm)
Sep 24, 2025
Omni Wireguard SideroLink potential escape
Low
CVE-2025-59824
was published
for
github.com/siderolabs/omni
(Go)
Sep 24, 2025
Mangati NovoSGA XSS vulnerability in /admin
Low
CVE-2025-10909
was published
for
novosga/novosga
(Composer)
Sep 24, 2025
min-document vulnerable to prototype pollution
Low
CVE-2025-57352
was published
for
min-document
(npm)
Sep 24, 2025
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a...
Low
Unreviewed
CVE-2025-23340
was published
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API