GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,139 advisories
Filter by severity
An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy...
Moderate
Unreviewed
CVE-2025-55146
was published
Sep 9, 2025
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6,...
Moderate
Unreviewed
CVE-2025-8711
was published
Sep 9, 2025
Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local...
Moderate
Unreviewed
CVE-2023-21483
was published
Sep 9, 2025
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute...
Moderate
Unreviewed
CVE-2025-56435
was published
Sep 9, 2025
Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to...
Moderate
Unreviewed
CVE-2025-21037
was published
Sep 9, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2025-20280
was published
Sep 9, 2025
Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged...
Moderate
Unreviewed
CVE-2025-21036
was published
Sep 9, 2025
A vulnerability in Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to...
Moderate
Unreviewed
CVE-2025-20291
was published
Sep 9, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
Moderate
Unreviewed
CVE-2025-20270
was published
Sep 9, 2025
An OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1...
Moderate
Unreviewed
CVE-2025-56498
was published
Sep 9, 2025
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts...
Moderate
Unreviewed
CVE-2025-9920
was published
Sep 9, 2025
A security vulnerability has been detected in Campcodes Sales and Inventory System 1.0. Affected...
Moderate
Unreviewed
CVE-2025-9922
was published
Sep 9, 2025
A weakness has been identified in code-projects POS Pharmacy System 1.0. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-9921
was published
Sep 9, 2025
A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown...
Moderate
Unreviewed
CVE-2025-10068
was published
Sep 7, 2025
Slink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views...
Moderate
Unreviewed
CVE-2025-55944
was published
Sep 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check...
Moderate
Unreviewed
CVE-2024-47704
was published
Oct 21, 2024
A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown...
Moderate
Unreviewed
CVE-2025-10107
was published
Sep 9, 2025
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7...
Moderate
Unreviewed
CVE-2025-53609
was published
Sep 9, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection')...
Moderate
Unreviewed
CVE-2024-45325
was published
Sep 9, 2025
A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by...
Moderate
Unreviewed
CVE-2025-47416
was published
Sep 9, 2025
SolidInvoice 2.3.7 and v.2.3.8 is vulnerable to Cross Site Scripting (XSS) in the client's...
Moderate
Unreviewed
CVE-2025-55580
was published
Aug 29, 2025
SolidInvoice 2.3.7 and fixed in v.2.3.8 is vulnerable to Cross Site Scripting (XSS) in the Tax...
Moderate
Unreviewed
CVE-2025-55579
was published
Aug 29, 2025
A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-9665
was published
Aug 29, 2025
A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue...
Moderate
Unreviewed
CVE-2025-9610
was published
Aug 29, 2025
A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve...
Moderate
Unreviewed
CVE-2025-34521
was published
Aug 28, 2025
ProTip!
Advisories are also available from the
GraphQL API