GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
165 advisories
Filter by severity
Insecure default settings have been found in recorder products provided by Yokogawa Electric...
Critical
Unreviewed
CVE-2025-1863
was published
Apr 18, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Moderate
Unreviewed
CVE-2025-2442
was published
Apr 9, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Moderate
Unreviewed
CVE-2025-2441
was published
Apr 9, 2025
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an...
Low
Unreviewed
CVE-2025-27443
was published
Apr 8, 2025
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource...
Moderate
Unreviewed
CVE-2025-29985
was published
Apr 8, 2025
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have...
Moderate
Unreviewed
CVE-2025-27809
was published
Mar 25, 2025
Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver...
High
Unreviewed
CVE-2024-41995
was published
Aug 6, 2024
An unauthenticated remote attacker can gain limited information of the PLC network but the user...
Moderate
Unreviewed
CVE-2024-41975
was published
Mar 18, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Critical
Unreviewed
CVE-2025-1960
was published
Mar 12, 2025
A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects...
Moderate
Unreviewed
CVE-2025-2129
was published
Mar 9, 2025
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users...
Moderate
Unreviewed
CVE-2024-0387
was published
Feb 26, 2024
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution...
High
Unreviewed
CVE-2022-2196
was published
Jan 9, 2023
Apache ActiveMQ's default configuration doesn't secure the API web context
High
CVE-2024-32114
was published
for
org.apache.activemq:apache-activemq
(Maven)
May 2, 2024
Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers...
Moderate
Unreviewed
CVE-2024-48122
was published
Jan 15, 2025
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default...
Critical
Unreviewed
CVE-2022-24706
was published
Apr 27, 2022
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g.,...
Low
Unreviewed
CVE-2024-56433
was published
Dec 26, 2024
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will...
High
Unreviewed
CVE-2022-48492
was published
Jun 19, 2023
Configuration defects in the secure OS module.Successful exploitation of this vulnerability will...
High
Unreviewed
CVE-2022-48493
was published
Jun 19, 2023
Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)
Critical
CVE-2024-25610
was published
for
com.liferay.portal:com.liferay.portal.web
(Maven)
Feb 20, 2024
OpenStack Nova uses insecure keystone middleware tmpdir by default
Moderate
CVE-2013-2030
was published
for
python-keystoneclient
(pip)
May 17, 2022
Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote...
High
Unreviewed
CVE-2024-47295
was published
Oct 1, 2024
Filament has exported files stored in default (`public`) filesystem if not reconfigured
Low
CVE-2024-51758
was published
for
filament/actions
(Composer)
Nov 7, 2024
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value,...
Moderate
Unreviewed
CVE-2020-11917
was published
Nov 7, 2024
Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in...
High
Unreviewed
CVE-2024-25972
was published
Mar 1, 2024
Firefox normally asks for confirmation before asking the operating system to find an application...
High
Unreviewed
CVE-2024-8383
was published
Sep 3, 2024
ProTip!
Advisories are also available from the
GraphQL API