GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,868
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,116
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,055 advisories
Filter by severity
Infrahub: Deleted and expired API tokens can still authenticate
Moderate
CVE-2025-59036
was published
for
infrahub-server
(pip)
Sep 10, 2025
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
Indico vulnerable to Cross-Site Scripting via LaTeX math code
Moderate
CVE-2025-59035
was published
for
indico
(pip)
Sep 10, 2025
Indico may disclose unauthorized user details access via legacy API
Moderate
CVE-2025-59034
was published
for
indico
(pip)
Sep 10, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
Liferay Portal exposes 500 status when attempting login with a deleted client secret
Moderate
CVE-2025-43777
was published
for
com.liferay:com.liferay.portal.security.sso.openid.connect.impl
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through fieldset name in Kaleo Forms Admin
Moderate
CVE-2025-43778
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to SSRF through custom object attachment fields
Moderate
CVE-2025-43763
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
Moderate
Unreviewed
CVE-2025-8712
was published
Sep 9, 2025
Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as ...
Moderate
Unreviewed
CVE-2025-44593
was published
Sep 9, 2025
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated...
Moderate
Unreviewed
CVE-2025-20248
was published
Sep 10, 2025
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.45 through 7.4.3.128, and...
Moderate
Unreviewed
CVE-2025-43785
was published
Sep 10, 2025
A vulnerability in the management interface access control list (ACL) processing feature in Cisco...
Moderate
Unreviewed
CVE-2025-20159
was published
Sep 10, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Plaintext...
Moderate
Unreviewed
CVE-2025-43938
was published
Sep 10, 2025
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user...
Moderate
Unreviewed
CVE-2025-8681
was published
Sep 10, 2025
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: ...
Moderate
Unreviewed
CVE-2025-43886
was published
Sep 10, 2025
A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0....
Moderate
Unreviewed
CVE-2025-9848
was published
Sep 10, 2025
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM ...
Moderate
Unreviewed
CVE-2025-20330
was published
Sep 10, 2025
A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is...
Moderate
Unreviewed
CVE-2025-9847
was published
Sep 10, 2025
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an...
Moderate
Unreviewed
CVE-2025-10025
was published
Sep 5, 2025
A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an...
Moderate
Unreviewed
CVE-2025-20328
was published
Sep 10, 2025
A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects...
Moderate
Unreviewed
CVE-2025-9919
was published
Sep 10, 2025
A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter...
Moderate
Unreviewed
CVE-2025-57538
was published
Sep 9, 2025
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field...
Moderate
Unreviewed
CVE-2025-57540
was published
Sep 9, 2025
Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute...
Moderate
Unreviewed
CVE-2025-52277
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API