GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
177 advisories
Filter by severity
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Thunderbird displayed an incorrect sender address if the From field of an email used the invalid...
Moderate
Unreviewed
CVE-2025-0510
was published
Feb 4, 2025
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-54111
was published
Dec 12, 2024
Duplicate Advisory: WildFly Elytron OpenID Connect Client Extension authorization code injection attack
Moderate
GHSA-4v5x-9m47-cqr2
was published
for
org.wildfly:wildfly-elytron-oidc-client-subsystem
(Maven)
Dec 9, 2024
•
withdrawn
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing...
Moderate
Unreviewed
CVE-2024-52548
was published
Dec 3, 2024
quic-go affected by an ICMP Packet Too Large Injection Attack on Linux
Moderate
CVE-2024-53259
was published
for
github.com/quic-go/quic-go
(Go)
Dec 2, 2024
sigstore-java has vulnerability with bundle verification
Moderate
CVE-2024-53267
was published
for
dev.sigstore:sigstore-java
(Maven)
Nov 26, 2024
IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a...
Moderate
Unreviewed
CVE-2022-33861
was published
Nov 25, 2024
OpenStack Neutron can use an incorrect ID during policy enforcement
Moderate
CVE-2024-53916
was published
for
neutron
(pip)
Nov 25, 2024
Moodle vulnerable to cache poisoning via injection into storage
Moderate
CVE-2024-43428
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data...
Moderate
Unreviewed
CVE-2024-47254
was published
Nov 5, 2024
In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges...
Moderate
Unreviewed
CVE-2024-47255
was published
Nov 5, 2024
The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional...
Moderate
Unreviewed
CVE-2024-47123
was published
Sep 26, 2024
The goTenna Pro ATAK Plugin use AES CTR mode for short, encrypted
messages without any...
Moderate
Unreviewed
CVE-2024-43108
was published
Sep 26, 2024
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2024-23922
was published
Sep 23, 2024
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in...
Moderate
Unreviewed
CVE-2022-4533
was published
Sep 19, 2024
Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always...
Moderate
Unreviewed
CVE-2024-25584
was published
Sep 6, 2024
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in...
Moderate
Unreviewed
CVE-2022-4539
was published
Aug 31, 2024
Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0...
Moderate
Unreviewed
CVE-2023-28865
was published
Aug 8, 2024
In regclient, pinned manifest digests may be ignored
Moderate
CVE-2025-24882
was published
for
github.com/regclient/regclient
(Go)
Aug 5, 2024
Matrix Tafnit v8
-
CWE-646: Reliance on File Name or Extension of Externally-Supplied File
Moderate
Unreviewed
CVE-2024-38432
was published
Jul 30, 2024
An attacker with access to the private network (the charger is connected to) or local access to...
Moderate
Unreviewed
CVE-2024-5684
was published
Jun 6, 2024
Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows...
Moderate
Unreviewed
CVE-2024-31341
was published
May 17, 2024
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for...
Moderate
Unreviewed
CVE-2024-27244
was published
May 15, 2024
ProTip!
Advisories are also available from the
GraphQL API