GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,583 advisories
Filter by severity
There is an out of bounds write vulnerability due to improper bounds checking resulting in an...
High
Unreviewed
CVE-2025-57778
was published
Sep 2, 2025
ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2025-6685
was published
Sep 2, 2025
There is a heap-based Buffer Overflow vulnerability due to improper bounds checking when parsing...
High
Unreviewed
CVE-2025-57775
was published
Sep 2, 2025
Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution...
High
Unreviewed
CVE-2025-7976
was published
Sep 2, 2025
There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This...
High
Unreviewed
CVE-2025-9188
was published
Sep 2, 2025
There is an out of bounds write vulnerability due to improper bounds checking resulting in a...
High
Unreviewed
CVE-2025-9189
was published
Sep 2, 2025
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation...
High
Unreviewed
CVE-2025-8300
was published
Sep 2, 2025
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation...
High
Unreviewed
CVE-2025-8302
was published
Sep 2, 2025
Realtek RTL8811AU rtwlanu.sys N6CSet_DOT11_CIPHER_DEFAULT_KEY Heap-based Buffer Overflow Local...
High
Unreviewed
CVE-2025-8301
was published
Sep 2, 2025
Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local...
High
Unreviewed
CVE-2025-8299
was published
Sep 2, 2025
Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability...
High
Unreviewed
CVE-2025-8613
was published
Sep 2, 2025
Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-7975
was published
Sep 2, 2025
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities,...
High
Unreviewed
CVE-2025-54599
was published
Sep 2, 2025
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference...
High
Unreviewed
CVE-2025-57612
was published
Sep 2, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool
High
CVE-2025-58358
was published
for
mcp-markdownify-server
(npm)
Sep 2, 2025
Command Injection via sonarqube-scan-action GitHub Action
High
CVE-2025-58178
was published
for
SonarSource/sonarqube-scan-action
(GitHub Actions)
Sep 2, 2025
arenavec has multiple memory corruption vulnerabilities in safe APIs
High
GHSA-3632-54q8-m96x
was published
for
arenavec
(Rust)
Sep 2, 2025
PocketMine-MP `ResourcePackDataInfoPacket` amplification vulnerability due to lack of resource pack sequence status checking
High
GHSA-fqqv-56h5-f57g
was published
for
pocketmine/pocketmine-mp
(Composer)
Sep 2, 2025
ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
High
CVE-2025-57808
was published
for
esphome
(pip)
Sep 2, 2025
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor...
High
Unreviewed
CVE-2025-2413
was published
Sep 2, 2025
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element...
High
Unreviewed
CVE-2025-9815
was published
Sep 2, 2025
Undertow MadeYouReset HTTP/2 DDoS Vulnerability
High
CVE-2025-9784
was published
for
io.undertow:undertow-core
(Maven)
Sep 2, 2025
In BootRom, there's a possible unchecked command index. This could lead to local escalation of...
High
Unreviewed
CVE-2022-38695
was published
Sep 2, 2025
A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code...
High
Unreviewed
CVE-2025-9791
was published
Sep 2, 2025
ProTip!
Advisories are also available from the
GraphQL API