GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,847 advisories
Filter by severity
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft...
Critical
Unreviewed
CVE-2025-10226
was published
Sep 10, 2025
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in...
Critical
Unreviewed
CVE-2025-10220
was published
Sep 10, 2025
An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response...
Critical
Unreviewed
CVE-2025-9943
was published
Sep 10, 2025
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via...
Critical
Unreviewed
CVE-2025-58462
was published
Sep 9, 2025
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated...
Critical
Unreviewed
CVE-2025-57633
was published
Sep 9, 2025
An authentication bypass vulnerability allows remote attackers to gain administrative privileges...
Critical
Unreviewed
CVE-2025-10159
was published
Sep 9, 2025
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api...
Critical
Unreviewed
CVE-2025-44594
was published
Sep 9, 2025
CWE-1242: Inclusion of Undocumented Features
Critical
Unreviewed
CVE-2025-55050
was published
Sep 9, 2025
Use of Default Cryptographic Key (CWE-1394)
Critical
Unreviewed
CVE-2025-55049
was published
Sep 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow allows Code Injection. This issue...
Critical
Unreviewed
CVE-2025-58997
was published
Sep 9, 2025
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an...
Critical
Unreviewed
CVE-2025-55232
was published
Sep 9, 2025
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation...
Critical
Unreviewed
CVE-2025-54261
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography. This issue affects...
Critical
Unreviewed
CVE-2025-47579
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-47569
was published
Sep 9, 2025
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material...
Critical
Unreviewed
CVE-2025-32486
was published
Sep 9, 2025
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect...
Critical
Unreviewed
CVE-2025-10183
was published
Sep 9, 2025
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an...
Critical
Unreviewed
CVE-2025-9994
was published
Sep 9, 2025
Magento Community Edition Improper Input Validation vulnerability
Critical
CVE-2025-54236
was published
for
magento/community-edition
(Composer)
Sep 9, 2025
A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions...
Critical
Unreviewed
CVE-2025-40804
was published
Sep 9, 2025
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2025-10134
was published
Sep 9, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 ...
Critical
Unreviewed
CVE-2025-40795
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API