GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
11,069 advisories
Filter by severity
A relative path traversal vulnerability has been reported to affect Download Station. If a remote...
Low
Unreviewed
CVE-2025-58463
was published
Nov 7, 2025
A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The...
Low
Unreviewed
CVE-2025-58469
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a...
Low
Unreviewed
CVE-2025-58465
was published
Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-52865
was published
Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-53412
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a...
Low
Unreviewed
CVE-2025-57706
was published
Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-53408
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote...
Low
Unreviewed
CVE-2025-54168
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-53411
was published
Nov 7, 2025
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to...
Low
Unreviewed
CVE-2025-11219
was published
Nov 7, 2025
Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to...
Low
Unreviewed
CVE-2025-21077
was published
Nov 5, 2025
This issue was addressed by restricting options offered on a locked device. This issue is fixed...
Low
Unreviewed
CVE-2025-43408
was published
Nov 4, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and...
Low
Unreviewed
CVE-2025-43423
was published
Nov 4, 2025
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma...
Low
Unreviewed
CVE-2025-43395
was published
Nov 4, 2025
A denial-of-service issue was addressed with improved input validation. This issue is fixed in...
Low
Unreviewed
CVE-2025-43365
was published
Nov 4, 2025
A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An...
Low
Unreviewed
CVE-2025-43309
was published
Nov 4, 2025
Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass...
Low
Unreviewed
CVE-2025-8558
was published
Nov 3, 2025
A vulnerability was identified in fushengqian fuint up to...
Low
Unreviewed
CVE-2025-12623
was published
Nov 3, 2025
A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is...
Low
Unreviewed
CVE-2025-12615
was published
Nov 3, 2025
/etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4:...
Low
Unreviewed
CVE-2025-12603
was published
Nov 1, 2025
/etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1...
Low
Unreviewed
CVE-2025-12602
was published
Nov 1, 2025
If the value passed to os.path.expandvars() is user-controlled a
performance degradation is...
Low
Unreviewed
CVE-2025-6075
was published
Oct 31, 2025
IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on...
Low
Unreviewed
CVE-2025-36249
was published
Oct 31, 2025
Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential...
Low
Unreviewed
CVE-2025-64352
was published
Oct 31, 2025
Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows...
Low
Unreviewed
CVE-2025-64350
was published
Oct 31, 2025
ProTip!
Advisories are also available from the
GraphQL API