GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
112,524 advisories
Filter by severity
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet...
High
Unreviewed
CVE-2025-54406
was published
Oct 7, 2025
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of...
High
Unreviewed
CVE-2025-54399
was published
Oct 7, 2025
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of...
High
Unreviewed
CVE-2025-54401
was published
Oct 7, 2025
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500...
High
Unreviewed
CVE-2025-54403
was published
Oct 7, 2025
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet...
High
Unreviewed
CVE-2025-54405
was published
Oct 7, 2025
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500...
High
Unreviewed
CVE-2025-54404
was published
Oct 7, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2021-22291
was published
Oct 7, 2025
A SQL Injection vulnerability was discovered in the Alert functionality due to improper...
High
Unreviewed
CVE-2025-40886
was published
Oct 7, 2025
A path traversal vulnerability was discovered in the Time Machine functionality due to missing...
High
Unreviewed
CVE-2025-40889
was published
Oct 7, 2025
Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by...
High
Unreviewed
CVE-2025-50505
was published
Oct 7, 2025
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via...
High
Unreviewed
CVE-2025-25009
was published
Oct 7, 2025
An access control vulnerability was discovered in the CLI functionality due to a specific access...
High
Unreviewed
CVE-2025-3719
was published
Oct 7, 2025
A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1...
High
Unreviewed
CVE-2025-48826
was published
Oct 7, 2025
A vulnerability was determined in Tenda AC15 15.03.05.18. This affects an unknown function of the...
High
Unreviewed
CVE-2025-11387
was published
Oct 7, 2025
A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the...
High
Unreviewed
CVE-2025-11385
was published
Oct 7, 2025
A vulnerability was identified in Tenda AC15 15.03.05.18. This impacts an unknown function of the...
High
Unreviewed
CVE-2025-11388
was published
Oct 7, 2025
A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function...
High
Unreviewed
CVE-2025-11386
was published
Oct 7, 2025
A security flaw has been discovered in Tenda AC15 15.03.05.18. Affected is an unknown function of...
High
Unreviewed
CVE-2025-11389
was published
Oct 7, 2025
A vulnerability has been found in UTT 1250GW up to v2v3.2.2-200710. Affected by this...
High
Unreviewed
CVE-2025-11355
was published
Oct 7, 2025
A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function...
High
Unreviewed
CVE-2025-11356
was published
Oct 7, 2025
The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before...
High
Unreviewed
CVE-2025-10162
was published
Oct 7, 2025
pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
High
CVE-2025-11362
was published
for
pdfmake
(npm)
Oct 7, 2025
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass...
High
Unreviewed
CVE-2025-34251
was published
Oct 7, 2025
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
High
CVE-2025-59152
was published
for
litestar
(pip)
Oct 6, 2025
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server ...
High
Unreviewed
CVE-2025-60967
was published
Oct 6, 2025
ProTip!
Advisories are also available from the
GraphQL API