GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
On BIG-IP systems, undisclosed traffic can cause data corruption and unauthorized data...
Moderate
Unreviewed
CVE-2025-58424
was published
Oct 15, 2025
Generation of Predictable Numbers or Identifiers vulnerability in B&R Industrial Automation...
Low
Unreviewed
CVE-2025-3449
was published
Oct 7, 2025
The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's...
Moderate
Unreviewed
CVE-2025-59452
was published
Oct 6, 2025
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's...
Moderate
Unreviewed
CVE-2024-10603
was published
Jan 30, 2025
When batch jobs are executed by pgAgent, a script is created in a temporary directory and then...
Moderate
Unreviewed
CVE-2025-0218
was published
Jan 7, 2025
The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions...
Moderate
Unreviewed
CVE-2024-12034
was published
Dec 24, 2024
Salt preflight script could be attacker controlled
Moderate
CVE-2023-34049
was published
for
salt
(pip)
Nov 14, 2024
The devices are vulnerable to session hijacking due to insufficient
entropy in its session ID...
Critical
Unreviewed
CVE-2024-47945
was published
Oct 15, 2024
JUJU_CONTEXT_ID is a predictable authentication secret
Moderate
CVE-2024-7558
was published
for
github.com/juju/juju
(Go)
Oct 3, 2024
Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If...
Moderate
Unreviewed
CVE-2024-28957
was published
Apr 15, 2024
Puppet uses predictable filenames, allowing arbitrary file overwrite
Moderate
CVE-2011-3871
was published
for
puppet
(RubyGems)
May 14, 2022
Ratpack's default client side session signing key is highly predictable
Moderate
CVE-2021-29480
was published
for
io.ratpack:ratpack-session
(Maven)
Jul 1, 2021
Predictable SIF UUID Identifiers in github.com/sylabs/sif
High
CVE-2021-29499
was published
for
github.com/sylabs/sif
(Go)
May 18, 2021
ProTip!
Advisories are also available from the
GraphQL API