GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,144
NuGet
735
pip
3,947
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
293,351 advisories
Filter by severity
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that...
High
Unreviewed
CVE-2025-7425
was published
Jul 10, 2025
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in...
Critical
Unreviewed
CVE-2025-52053
was published
Sep 15, 2025
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical....
Moderate
Unreviewed
CVE-2025-7099
was published
Jul 7, 2025
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: limit repeated...
Unknown
Unreviewed
CVE-2025-38501
was published
Aug 16, 2025
A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-7102
was published
Jul 7, 2025
A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2025-7101
was published
Jul 7, 2025
A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows...
Moderate
Unreviewed
CVE-2024-6768
was published
Aug 12, 2024
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2024-30080
was published
Jun 11, 2024
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was...
Unknown
Unreviewed
CVE-2025-55777
was published
Sep 15, 2025
A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The...
Moderate
Unreviewed
CVE-2025-59328
was published
Sep 15, 2025
IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another...
Moderate
Unreviewed
CVE-2025-36082
was published
Sep 15, 2025
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111,...
Moderate
Unreviewed
CVE-2025-43791
was published
Sep 15, 2025
Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and...
Low
Unreviewed
CVE-2025-43792
was published
Sep 15, 2025
Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2...
Moderate
Unreviewed
CVE-2025-52344
was published
Sep 15, 2025
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories...
High
Unreviewed
CVE-2025-10491
was published
Sep 15, 2025
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing...
High
Unreviewed
CVE-2025-57248
was published
Sep 15, 2025
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that...
High
Unreviewed
CVE-2025-10203
was published
Sep 15, 2025
Open Web Analytics (OWA) before 1.8.1 allows SQL injection.
Moderate
Unreviewed
CVE-2025-59397
was published
Sep 15, 2025
A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src...
Moderate
Unreviewed
CVE-2025-10471
was published
Sep 15, 2025
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker...
Critical
Unreviewed
CVE-2025-47981
was published
Jul 8, 2025
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled...
High
Unreviewed
CVE-2025-8941
was published
Aug 13, 2025
Improper link resolution before file access ('link following') in Windows Update Service allows...
High
Unreviewed
CVE-2025-48799
was published
Jul 8, 2025
A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML...
Critical
Unreviewed
CVE-2025-49796
was published
Jun 16, 2025
A vulnerability has been identified in the libarchive library, specifically within the...
Low
Unreviewed
CVE-2025-5914
was published
Jun 9, 2025
A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath...
Critical
Unreviewed
CVE-2025-49794
was published
Jun 16, 2025
ProTip!
Advisories are also available from the
GraphQL API