GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,489
Maven
5,000+
npm
4,106
NuGet
735
pip
3,928
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
12,416 advisories
Filter by severity
Apache DolphinScheduler Incorrect Default Permissions Vulnerability
Low
CVE-2024-43166
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 3, 2025
OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a...
Low
Unreviewed
CVE-2025-8662
was published
Sep 3, 2025
Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack...
Low
Unreviewed
CVE-2025-41000
was published
Sep 3, 2025
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a...
Low
Unreviewed
CVE-2025-31286
was published
Apr 2, 2025
Foxit PDF Reader JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This...
Low
Unreviewed
CVE-2025-9323
was published
Sep 2, 2025
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This...
Low
Unreviewed
CVE-2025-9324
was published
Sep 2, 2025
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This...
Low
Unreviewed
CVE-2025-9327
was published
Sep 2, 2025
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This...
Low
Unreviewed
CVE-2025-9325
was published
Sep 2, 2025
Realtek RTL8811AU rtwlanu.sys N6CQueryInformationHandleCustomized11nOids Out-Of-Bounds Read...
Low
Unreviewed
CVE-2025-8298
was published
Sep 2, 2025
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability...
Low
Unreviewed
CVE-2025-7974
was published
Sep 2, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Low
CVE-2025-58161
was published
for
mobsf
(pip)
Sep 2, 2025
Tracing logging user input may result in poisoning logs with ANSI escape sequences
Low
CVE-2025-58160
was published
for
tracing-subscriber
(Rust)
Aug 29, 2025
A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an...
Low
Unreviewed
CVE-2025-9778
was published
Sep 2, 2025
Improper Privilege Management in djangorestframework-simplejwt
Low
CVE-2024-22513
was published
for
djangorestframework-simplejwt
(pip)
Mar 16, 2024
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown...
Low
Unreviewed
CVE-2025-9731
was published
Aug 31, 2025
Opencast has a partial path traversal vulnerability in UI config
Low
CVE-2025-55202
was published
for
org.opencastproject:opencast-user-interface-configuration
(Maven)
Aug 29, 2025
Exiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
Low
CVE-2025-55304
was published
for
Exiv2
(pip)
Aug 29, 2025
Exiv2 Segmentation Faults in Exiv2::EpsImage::writeMetadata() via crafted EPS file
Low
CVE-2025-54080
was published
for
Exiv2
(pip)
Aug 29, 2025
Mattermost Fails to Properly Validate Team Role Modification
Low
CVE-2025-53971
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Lack of Access Control Validation
Low
CVE-2025-49810
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Server SSRF Vulnerability via the Agents Plugin
Low
CVE-2025-47700
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54364
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
Low
CVE-2025-54363
was published
for
knack
(pip)
Aug 20, 2025
•
withdrawn
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker...
Low
Unreviewed
CVE-2025-44015
was published
Aug 29, 2025
A buffer overflow vulnerability has been reported to affect several QNAP operating system...
Low
Unreviewed
CVE-2025-30265
was published
Aug 29, 2025
ProTip!
Advisories are also available from the
GraphQL API