GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,201 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Animesh Kumar Advanced Speed Increaser. This...
Moderate
Unreviewed
CVE-2025-31753
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31889
was published
Apr 1, 2025
Missing Authorization vulnerability in WP Messiah WP Mobile Bottom Menu allows Exploiting...
Moderate
Unreviewed
CVE-2025-31525
was published
Apr 1, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-31550
was published
Apr 1, 2025
Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images allows Exploiting...
Moderate
Unreviewed
CVE-2025-30853
was published
Apr 1, 2025
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-929m-phjg-qwcc
was published
for
mathlive
(npm)
Apr 1, 2025
•
withdrawn
An issue in hackathon-starter v.8.1.0 allows a remote attacker to escalate privileges via the...
Moderate
Unreviewed
CVE-2025-29036
was published
Apr 1, 2025
Ouch Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
Moderate
CVE-2024-13941
was published
for
ouch
(Rust)
Apr 1, 2025
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via...
Moderate
Unreviewed
CVE-2003-20001
was published
Apr 1, 2025
An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module,...
Moderate
Unreviewed
CVE-2025-26055
was published
Apr 1, 2025
A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot...
Moderate
Unreviewed
CVE-2025-26056
was published
Apr 1, 2025
Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field...
Moderate
Unreviewed
CVE-2025-26054
was published
Apr 1, 2025
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow...
Moderate
Unreviewed
CVE-2025-25041
was published
Apr 1, 2025
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege...
Moderate
Unreviewed
CVE-2025-28131
was published
Apr 1, 2025
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse...
Moderate
Unreviewed
CVE-2025-28132
was published
Apr 1, 2025
CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within ...
Moderate
Unreviewed
CVE-2025-29208
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
sched: address a potential...
Moderate
Unreviewed
CVE-2025-21980
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
ice: fix memory leak in aRFS...
Moderate
Unreviewed
CVE-2025-21981
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
mm: fix kernel BUG when...
Moderate
Unreviewed
CVE-2025-21984
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: nuvoton: npcm8xx:...
Moderate
Unreviewed
CVE-2025-21982
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix integer overflow...
Moderate
Unreviewed
CVE-2025-21963
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
gpio: aggregator: protect...
Moderate
Unreviewed
CVE-2025-21943
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix type confusion...
Moderate
Unreviewed
CVE-2025-21947
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla1280: Fix kernel...
Moderate
Unreviewed
CVE-2025-21957
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
eth: bnxt: fix truesize for...
Moderate
Unreviewed
CVE-2025-21961
was published
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API