GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,575 advisories
Filter by severity
In multiple locations, there is a possible one-time permission bypass due to a logic error in the...
High
Unreviewed
CVE-2025-48547
was published
Sep 4, 2025
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due...
High
Unreviewed
CVE-2025-32333
was published
Sep 4, 2025
In multiple locations, there is a possible way to hijack the Launcher app due to a logic error in...
High
Unreviewed
CVE-2025-0089
was published
Sep 4, 2025
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible DoS of a device...
High
Unreviewed
CVE-2025-48553
was published
Sep 4, 2025
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch...
High
Unreviewed
CVE-2025-48546
was published
Sep 4, 2025
In parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without...
High
Unreviewed
CVE-2025-26443
was published
Sep 5, 2025
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a...
High
Unreviewed
CVE-2025-26462
was published
Sep 5, 2025
In executeAppFunction of AppSearchManagerService.java, there is a possible background activity...
High
Unreviewed
CVE-2025-26464
was published
Sep 4, 2025
In multiple functions of LocationProviderManager.java, there is a possible background activity...
High
Unreviewed
CVE-2025-26458
was published
Sep 5, 2025
Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and...
High
Unreviewed
CVE-2014-9196
was published
May 17, 2022
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote...
High
Unreviewed
CVE-2014-9195
was published
May 14, 2022
pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
High
CVE-2025-9636
was published
for
pgadmin4
(pip)
Sep 5, 2025
TkEasyGUI Affected by Uncontrolled Search Path Element Issue
High
CVE-2025-55671
was published
for
TkEasyGUI
(pip)
Sep 5, 2025
Liferay Portal and Liferay DXP Vulnerable to SQL Injection via the Layout Module
High
CVE-2022-42121
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Inefficient Regular Expression Complexity in Liferay Portal
High
CVE-2022-42124
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Path Traversal in Liferay Portal
High
CVE-2022-42123
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
In FrpBypassAlertActivity of FrpBypassAlertActivity.java, there is a possible way to bypass FRP...
High
Unreviewed
CVE-2025-22414
was published
Sep 4, 2025
In maybeShowDialog of ControlsSettingsDialogManager.kt, there is a possible overlay of the...
High
Unreviewed
CVE-2025-32350
was published
Sep 4, 2025
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent...
High
Unreviewed
CVE-2025-32321
was published
Sep 4, 2025
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a...
High
Unreviewed
CVE-2025-48531
was published
Sep 4, 2025
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to...
High
Unreviewed
CVE-2025-32327
was published
Sep 4, 2025
In multiple locations, there is a possible way to read files belonging to other apps due to SQL...
High
Unreviewed
CVE-2025-48544
was published
Sep 4, 2025
In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible...
High
Unreviewed
CVE-2025-22441
was published
Sep 4, 2025
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent...
High
Unreviewed
CVE-2025-32326
was published
Sep 4, 2025
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without...
High
Unreviewed
CVE-2025-48523
was published
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API