GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
322 advisories
Filter by severity
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a...
Moderate
Unreviewed
CVE-2025-26637
was published
Apr 8, 2025
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol...
Moderate
Unreviewed
CVE-2023-23589
was published
Jan 14, 2023
In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation...
High
Unreviewed
CVE-2023-20919
was published
Jan 26, 2023
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful...
Critical
Unreviewed
CVE-2023-52378
was published
Feb 18, 2024
In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config...
High
Unreviewed
CVE-2024-0014
was published
Feb 16, 2024
A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4,...
Moderate
Unreviewed
CVE-2024-23284
was published
Mar 8, 2024
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for...
High
Unreviewed
CVE-2023-42938
was published
Mar 14, 2024
Because of a logical error in XSA-407 (Branch Type Confusion), the
mitigation is not applied...
High
Unreviewed
CVE-2024-31142
was published
May 16, 2024
Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a...
Moderate
Unreviewed
CVE-2024-1671
was published
Feb 21, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-20923
was published
Feb 17, 2024
events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability
Moderate
CVE-2024-38874
was published
for
jweiland/events2
(Composer)
Jun 21, 2024
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of...
Critical
Unreviewed
CVE-2022-48290
was published
Feb 9, 2023
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this...
High
Unreviewed
CVE-2022-48287
was published
Feb 9, 2023
Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote...
Moderate
Unreviewed
CVE-2023-0141
was published
Jan 10, 2023
Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed...
Moderate
Unreviewed
CVE-2023-0131
was published
Jan 10, 2023
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented...
Moderate
Unreviewed
CVE-2024-5691
was published
Jun 11, 2024
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP...
Moderate
Unreviewed
CVE-2022-48219
was published
Feb 15, 2024
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.1,...
High
Unreviewed
CVE-2024-44122
was published
Oct 28, 2024
In multiple files, there is a possible way to capture the device screen when disallowed by device...
High
Unreviewed
CVE-2024-0029
was published
Feb 16, 2024
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-24061
was published
Mar 11, 2025
A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A ...
High
Unreviewed
CVE-2024-56181
was published
Mar 11, 2025
A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 ...
High
Unreviewed
CVE-2024-56182
was published
Mar 11, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27665
was published
Mar 5, 2025
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-28286
was published
Apr 27, 2023
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2021-31982
was published
Jul 1, 2023
ProTip!
Advisories are also available from the
GraphQL API