GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,570 advisories
Filter by severity
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer...
High
Unreviewed
CVE-2025-32325
was published
Sep 4, 2025
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to...
High
Unreviewed
CVE-2025-32327
was published
Sep 4, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
High
CVE-2025-58179
was published
for
@astrojs/cloudflare
(npm)
Sep 4, 2025
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin...
High
Unreviewed
CVE-2025-57263
was published
Sep 4, 2025
It was possible to perform Remote Command Execution (RCE) via Java
RMI interface in the OpenEdge...
High
Unreviewed
CVE-2025-7388
was published
Sep 4, 2025
A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function...
High
Unreviewed
CVE-2025-9938
was published
Sep 4, 2025
Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to...
High
Unreviewed
CVE-2024-34598
was published
Sep 4, 2025
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an...
High
Unreviewed
CVE-2025-41032
was published
Sep 4, 2025
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an...
High
Unreviewed
CVE-2025-41033
was published
Sep 4, 2025
A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability...
High
Unreviewed
CVE-2025-41035
was published
Sep 4, 2025
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an...
High
Unreviewed
CVE-2025-41034
was published
Sep 4, 2025
In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic...
High
Unreviewed
CVE-2025-36905
was published
Sep 4, 2025
The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to...
High
Unreviewed
CVE-2025-6085
was published
Sep 4, 2025
The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to,...
High
Unreviewed
CVE-2025-9517
was published
Sep 4, 2025
The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient...
High
Unreviewed
CVE-2025-9518
was published
Sep 4, 2025
The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
High
Unreviewed
CVE-2025-9519
was published
Sep 4, 2025
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High
CVE-2025-6984
was published
for
langchain-community
(pip)
Sep 4, 2025
In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write...
High
Unreviewed
CVE-2025-36906
was published
Sep 4, 2025
There is a possible escalation of privilege due to test/debugging code left in a production build...
High
Unreviewed
CVE-2025-36899
was published
Sep 4, 2025
In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write...
High
Unreviewed
CVE-2025-36907
was published
Sep 4, 2025
In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation....
High
Unreviewed
CVE-2025-36903
was published
Sep 4, 2025
Liferay Portal Vulnerable to Denial of Service in Kaleo Forms Admin
High
CVE-2025-43772
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 4, 2025
In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to...
High
Unreviewed
CVE-2024-56190
was published
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API