GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
123,048 advisories
Filter by severity
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-7076
was published
Jul 6, 2025
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been declared as...
Moderate
Unreviewed
CVE-2025-7075
was published
Jul 6, 2025
A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This...
Moderate
Unreviewed
CVE-2025-7074
was published
Jul 5, 2025
Dradis through 4.16.0 allows referencing external images (resources) over HTTPS, instead of...
Moderate
Unreviewed
CVE-2023-50786
was published
Jul 5, 2025
The rustls crate 0.23.13 before 0.23.18 for Rust, when rustls::server::Acceptor::accept is used,...
Moderate
Unreviewed
CVE-2024-58254
was published
Jul 5, 2025
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell...
Moderate
Unreviewed
CVE-2025-47228
was published
Jul 5, 2025
The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf:...
Moderate
Unreviewed
CVE-2025-53605
was published
Jul 5, 2025
The web-push crate before 0.10.3 for Rust allows a denial of service (memory consumption) in the...
Moderate
Unreviewed
CVE-2025-53604
was published
Jul 5, 2025
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic....
Moderate
Unreviewed
CVE-2025-7070
was published
Jul 5, 2025
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the...
Moderate
Unreviewed
CVE-2025-7069
was published
Jul 4, 2025
Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator),...
Moderate
Unreviewed
CVE-2025-53602
was published
Jul 4, 2025
A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue...
Moderate
Unreviewed
CVE-2025-7068
was published
Jul 4, 2025
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects...
Moderate
Unreviewed
CVE-2025-7067
was published
Jul 4, 2025
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash...
Moderate
Unreviewed
CVE-2025-49600
was published
Jul 4, 2025
In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer...
Moderate
Unreviewed
CVE-2025-49601
was published
Jul 4, 2025
Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in...
Moderate
Unreviewed
CVE-2025-52497
was published
Jul 4, 2025
CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c...
Moderate
Unreviewed
CVE-2025-48172
was published
Jul 4, 2025
A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as...
Moderate
Unreviewed
CVE-2025-7061
was published
Jul 4, 2025
The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-6740
was published
Jul 4, 2025
Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2...
Moderate
Unreviewed
CVE-2025-6056
was published
Jul 4, 2025
Jirafeau normally prevents browser preview for text files due to the possibility that for example...
Moderate
Unreviewed
CVE-2025-7066
was published
Jul 4, 2025
Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store allows Exploiting...
Moderate
Unreviewed
CVE-2025-47634
was published
Jul 4, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-48231
was published
Jul 4, 2025
Weak Authentication vulnerability in AresIT WP Compress allows Authentication Abuse. This issue...
Moderate
Unreviewed
CVE-2025-47479
was published
Jul 4, 2025
Missing Authorization vulnerability in Gnuget MF Plus WPML allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49431
was published
Jul 4, 2025
ProTip!
Advisories are also available from the
GraphQL API