GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,152
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
9,819 advisories
Filter by severity
TYPO3 Workspaces Module Information Disclosure
High
CVE-2025-59018
was published
for
typo3/cms-workspaces
(Composer)
Sep 9, 2025
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The...
Low
Unreviewed
CVE-2025-40803
was published
Sep 9, 2025
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC...
Moderate
Unreviewed
CVE-2025-40757
was published
Sep 9, 2025
OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other...
Critical
Unreviewed
CVE-2025-22956
was published
Sep 8, 2025
A vulnerability was identified in D-Link DIR-852 up to 1.00CN B09. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2025-10093
was published
Sep 8, 2025
The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is...
Moderate
Unreviewed
CVE-2025-7368
was published
Sep 6, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint
Low
CVE-2025-58445
was published
for
github.com/runatlantis/atlantis
(Go)
Sep 5, 2025
In isContentUriForOtherUser of BluetoothOppSendFileInfo.java, there is a possible cross user data...
Moderate
Unreviewed
CVE-2025-26453
was published
Sep 5, 2025
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized...
Moderate
Unreviewed
CVE-2025-55242
was published
Sep 5, 2025
In multiple locations, there is a possible way to leak hidden work profile notifications due to a...
Moderate
Unreviewed
CVE-2025-48527
was published
Sep 4, 2025
Argo CD's Project API Token Exposes Repository Credentials
Critical
CVE-2025-55190
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 4, 2025
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High
CVE-2025-6984
was published
for
langchain-community
(pip)
Sep 4, 2025
Jenkins Git client Plugin file system information disclosure vulnerability
Moderate
CVE-2025-58458
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Sep 3, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore...
High
Unreviewed
CVE-2025-53694
was published
Sep 3, 2025
A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an...
Moderate
Unreviewed
CVE-2025-9842
was published
Sep 3, 2025
Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is...
Low
Unreviewed
CVE-2025-51643
was published
Aug 28, 2025
Valtimo scripting engine can be used to gain access to sensitive data or resources
Critical
CVE-2025-58059
was published
for
com.ritense.valtimo:core
(Maven)
Aug 28, 2025
Contao can disclose sensitive information in the news module
Moderate
CVE-2025-57757
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao discloses sensitive information in the front end search index
Moderate
CVE-2025-57756
was published
for
contao/contao
(Composer)
Aug 28, 2025
The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
High
Unreviewed
CVE-2024-13807
was published
Aug 28, 2025
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information...
High
Unreviewed
CVE-2023-7308
was published
Aug 28, 2025
A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series...
Moderate
Unreviewed
CVE-2025-20290
was published
Aug 27, 2025
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to...
Critical
Unreviewed
CVE-2024-39335
was published
Aug 26, 2025
Mahara before 24.04.9 exposes database connection information if the database becomes unreachable...
High
Unreviewed
CVE-2025-29992
was published
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API