GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,019
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,556 advisories
Filter by severity
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an...
High
Unreviewed
CVE-2025-26436
was published
Sep 5, 2025
In saveGlobalProxyLocked of DevicePolicyManagerService.java, there is a possible way to desync...
High
Unreviewed
CVE-2025-48552
was published
Sep 4, 2025
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a...
High
Unreviewed
CVE-2025-26435
was published
Sep 5, 2025
In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the...
High
Unreviewed
CVE-2025-26444
was published
Sep 5, 2025
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a...
High
Unreviewed
CVE-2025-32345
was published
Sep 4, 2025
In multiple locations, there is a possible one-time permission bypass due to a logic error in the...
High
Unreviewed
CVE-2025-48547
was published
Sep 4, 2025
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due...
High
Unreviewed
CVE-2025-32333
was published
Sep 4, 2025
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in...
High
Unreviewed
CVE-2025-0089
was published
Sep 4, 2025
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device...
High
Unreviewed
CVE-2025-48553
was published
Sep 4, 2025
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch...
High
Unreviewed
CVE-2025-48546
was published
Sep 4, 2025
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without...
High
Unreviewed
CVE-2025-26443
was published
Sep 5, 2025
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a...
High
Unreviewed
CVE-2025-26462
was published
Sep 5, 2025
In executeAppFunction of AppSearchManagerService.java, there is a possible background activity...
High
Unreviewed
CVE-2025-26464
was published
Sep 4, 2025
In multiple functions of LocationProviderManager.java, there is a possible background activity...
High
Unreviewed
CVE-2025-26458
was published
Sep 5, 2025
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and...
High
Unreviewed
CVE-2014-9196
was published
May 17, 2022
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote...
High
Unreviewed
CVE-2014-9195
was published
May 14, 2022
pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
High
CVE-2025-9636
was published
for
pgadmin4
(pip)
Sep 5, 2025
TkEasyGUI Affected by Uncontrolled Search Path Element Issue
High
CVE-2025-55671
was published
for
TkEasyGUI
(pip)
Sep 5, 2025
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module
High
CVE-2022-42121
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Inefficient Regular Expression Complexity in Liferay Portal
High
CVE-2022-42124
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Path Traversal in Liferay Portal
High
CVE-2022-42123
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP...
High
Unreviewed
CVE-2025-22414
was published
Sep 4, 2025
In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the...
High
Unreviewed
CVE-2025-32350
was published
Sep 4, 2025
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent...
High
Unreviewed
CVE-2025-32321
was published
Sep 4, 2025
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a...
High
Unreviewed
CVE-2025-48531
was published
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API