GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,678
Erlang
34
GitHub Actions
26
Go
2,265
Maven
5,000+
npm
3,918
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
38 advisories
Filter by severity
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS...
Moderate
Unreviewed
CVE-2025-24347
was published
Apr 30, 2025
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS...
Moderate
Unreviewed
CVE-2025-24348
was published
Apr 30, 2025
A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote...
High
Unreviewed
CVE-2025-24346
was published
Apr 30, 2025
A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote...
Moderate
Unreviewed
CVE-2025-24345
was published
Apr 30, 2025
Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
Moderate
Unreviewed
CVE-2025-46419
was published
Apr 24, 2025
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
High
CVE-2025-22868
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11...
Moderate
Unreviewed
CVE-2024-52362
was published
Mar 12, 2025
Improper Validation of Syntactic Correctness of Input vulnerability in Finder Fire Safety Finder...
High
Unreviewed
CVE-2024-12146
was published
Mar 6, 2025
In Modem, there is a possible memory corruption due to incorrect error handling. This could lead...
High
Unreviewed
CVE-2025-20644
was published
Mar 3, 2025
A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) ...
High
Unreviewed
CVE-2025-24812
was published
Feb 11, 2025
The initial code parsing the manifest did not check the content of the file names yet later code...
High
Unreviewed
CVE-2025-0638
was published
Jan 22, 2025
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi...
Low
Unreviewed
CVE-2024-8160
was published
Nov 26, 2024
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API...
Moderate
Unreviewed
CVE-2024-8772
was published
Nov 26, 2024
An authenticated user can provide a malformed ACL to the fileserver's StoreACL
RPC, causing the...
High
Unreviewed
CVE-2024-10396
was published
Nov 14, 2024
Eclipse Jetty URI parsing of invalid authority
Moderate
CVE-2024-6763
was published
for
org.eclipse.jetty:jetty-http
(Maven)
Oct 14, 2024
Denial of Service in TYPO3 Bookmark Toolbar
Low
CVE-2024-34537
was published
for
typo3/cms-backend
(Composer)
Oct 8, 2024
51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API...
Moderate
Unreviewed
CVE-2024-6173
was published
Sep 10, 2024
An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding...
High
Unreviewed
CVE-2024-39542
was published
Jul 11, 2024
An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7...
High
Unreviewed
CVE-2024-26507
was published
Jun 10, 2024
An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol...
High
Unreviewed
CVE-2024-21598
was published
Apr 12, 2024
A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS...
High
Unreviewed
CVE-2024-3384
was published
Apr 10, 2024
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input...
High
Unreviewed
CVE-2024-0218
was published
Apr 10, 2024
** DISPUTED ** An Improper Input Validation vulnerability affecting the FTP service running on...
Low
Unreviewed
CVE-2023-6950
was published
Apr 2, 2024
Express.js Open Redirect in malformed URLs
Moderate
CVE-2024-29041
was published
for
express
(npm)
Mar 25, 2024
An Improper Validation of Syntactic Correctness of Input vulnerability in Packet Forwarding...
High
Unreviewed
CVE-2024-21616
was published
Jan 12, 2024
ProTip!
Advisories are also available from the
GraphQL API