GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
165 advisories
Filter by severity
The CS5000 Fire Panel is vulnerable due to a default account that exists
on the panel. Even...
Critical
Unreviewed
CVE-2025-41438
was published
May 30, 2025
The Versa Director software exposes a number of services by default and allow attackers an easy...
Critical
Unreviewed
CVE-2025-24288
was published
Jun 19, 2025
Insecure Default Initialization of Resource vulnerability in Apache Solr
High
CVE-2024-45217
was published
for
org.apache.solr:solr
(Maven)
Oct 16, 2024
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain...
Critical
Unreviewed
CVE-2025-41672
was published
Jul 7, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure...
High
Unreviewed
CVE-2025-25271
was published
Jul 8, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
Moderate
CVE-2024-26267
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk...
High
Unreviewed
CVE-2025-44647
was published
Jul 21, 2025
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0...
High
Unreviewed
CVE-2017-12736
was published
May 13, 2022
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation...
Critical
Unreviewed
CVE-2025-7353
was published
Aug 14, 2025
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the...
High
Unreviewed
CVE-2024-6788
was published
Aug 13, 2024
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept...
Moderate
Unreviewed
CVE-2025-32330
was published
Sep 4, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for...
High
Unreviewed
CVE-2025-36222
was published
Sep 11, 2025
ProTip!
Advisories are also available from the
GraphQL API