GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,868
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,116
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,845 advisories
Filter by severity
Magento Community Edition Improper Input Validation vulnerability
Critical
CVE-2025-54236
was published
for
magento/community-edition
(Composer)
Sep 9, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Improper Neutralization of Special Elements used in a Command in Shell-quote
Critical
CVE-2021-42740
was published
for
shell-quote
(npm)
May 24, 2022
CodeceptJS's incomprehensive sanitation can lead to Command Injection
Critical
CVE-2025-57285
was published
for
codeceptjs
(npm)
Sep 8, 2025
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api...
Critical
Unreviewed
CVE-2025-44594
was published
Sep 9, 2025
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an...
Critical
Unreviewed
CVE-2025-9994
was published
Sep 9, 2025
Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in...
Critical
Unreviewed
CVE-2025-10220
was published
Sep 10, 2025
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft...
Critical
Unreviewed
CVE-2025-10226
was published
Sep 10, 2025
A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated...
Critical
Unreviewed
CVE-2025-57633
was published
Sep 9, 2025
An authentication bypass vulnerability allows remote attackers to gain administrative privileges...
Critical
Unreviewed
CVE-2025-10159
was published
Sep 9, 2025
OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via...
Critical
Unreviewed
CVE-2025-58462
was published
Sep 9, 2025
Use of Default Cryptographic Key (CWE-1394)
Critical
Unreviewed
CVE-2025-55049
was published
Sep 9, 2025
CWE-1242: Inclusion of Undocumented Features
Critical
Unreviewed
CVE-2025-55050
was published
Sep 9, 2025
A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows...
Critical
Unreviewed
CVE-2024-13979
was published
Aug 28, 2025
OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other...
Critical
Unreviewed
CVE-2025-22956
was published
Sep 8, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow allows Code Injection. This issue...
Critical
Unreviewed
CVE-2025-58997
was published
Sep 9, 2025
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation...
Critical
Unreviewed
CVE-2025-54261
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-47569
was published
Sep 9, 2025
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material...
Critical
Unreviewed
CVE-2025-32486
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in ThemeGoods Photography. This issue affects...
Critical
Unreviewed
CVE-2025-47579
was published
Sep 9, 2025
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an...
Critical
Unreviewed
CVE-2025-55232
was published
Sep 9, 2025
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4...
Critical
Unreviewed
CVE-2021-32024
was published
Dec 14, 2021
A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified...
Critical
Unreviewed
CVE-2025-34522
was published
Aug 28, 2025
ProTip!
Advisories are also available from the
GraphQL API