GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,540 advisories
Filter by severity
Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage
High
CVE-2025-59052
was published
for
@angular/platform-server
(npm)
Sep 10, 2025
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a...
High
Unreviewed
CVE-2025-10200
was published
Sep 10, 2025
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0...
High
Unreviewed
CVE-2025-10201
was published
Sep 10, 2025
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference...
High
Unreviewed
CVE-2025-57613
was published
Sep 10, 2025
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid...
High
Unreviewed
CVE-2025-57614
was published
Sep 10, 2025
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow...
High
Unreviewed
CVE-2025-57615
was published
Sep 10, 2025
Shopware: Reflective Cross Site-Scripting (XSS) in CMS components
High
GHSA-9v82-vcjx-m76j
was published
for
shopware/core
(Composer)
Sep 10, 2025
xml2rfc is vulnerable to arbitrary file reads through prepped files
High
GHSA-9mv7-3c64-mmqw
was published
for
xml2rfc
(pip)
Sep 10, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
High
CVE-2025-54376
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
PyInstaller has local privilege escalation vulnerability
High
CVE-2025-59042
was published
for
pyinstaller
(pip)
Sep 10, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Picklescan Bypass is Possible via File Extension Mismatch
High
GHSA-jgw4-cr84-mqxg
was published
for
picklescan
(pip)
Sep 10, 2025
Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
High
GHSA-mjqp-26hc-grxg
was published
for
picklescan
(pip)
Sep 10, 2025
If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and...
High
Unreviewed
CVE-2025-8696
was published
Sep 10, 2025
The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to...
High
Unreviewed
CVE-2025-50892
was published
Sep 10, 2025
Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint....
High
Unreviewed
CVE-2025-55976
was published
Sep 10, 2025
BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation...
High
Unreviewed
CVE-2025-57392
was published
Sep 10, 2025
A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software...
High
Unreviewed
CVE-2025-20340
was published
Sep 10, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper...
High
Unreviewed
CVE-2025-43885
was published
Sep 10, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper...
High
Unreviewed
CVE-2025-43884
was published
Sep 10, 2025
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s)...
High
Unreviewed
CVE-2025-43725
was published
Sep 10, 2025
Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of...
High
Unreviewed
CVE-2025-43888
was published
Sep 10, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect...
High
Unreviewed
CVE-2025-43887
was published
Sep 10, 2025
A vulnerability in the web-based management interface of Cisco Unified Communications Manager ...
High
Unreviewed
CVE-2025-20326
was published
Sep 10, 2025
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability...
High
Unreviewed
CVE-2025-57616
was published
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API