GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,549 advisories
Filter by severity
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an...
High
Unreviewed
CVE-2025-54106
was published
Sep 9, 2025
Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54112
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-53807
was published
Sep 9, 2025
Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker...
High
Unreviewed
CVE-2025-54093
was published
Sep 9, 2025
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized...
High
Unreviewed
CVE-2025-54099
was published
Sep 9, 2025
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54091
was published
Sep 9, 2025
Use after free in Windows Management Services allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-54103
was published
Sep 9, 2025
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to...
High
Unreviewed
CVE-2025-54102
was published
Sep 9, 2025
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-54098
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54092
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core allows Object...
High
Unreviewed
CVE-2025-53303
was published
Sep 9, 2025
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows...
High
Unreviewed
CVE-2025-49734
was published
Sep 9, 2025
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-53802
was published
Sep 9, 2025
Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-53801
was published
Sep 9, 2025
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-53805
was published
Sep 9, 2025
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-53800
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47694
was published
Sep 9, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-47695
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47570
was published
Sep 9, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-47571
was published
Sep 9, 2025
Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player allows Server...
High
Unreviewed
CVE-2025-49430
was published
Sep 9, 2025
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to...
High
Unreviewed
CVE-2025-49692
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress...
High
Unreviewed
CVE-2025-48101
was published
Sep 9, 2025
K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged...
High
Unreviewed
CVE-2025-52915
was published
Sep 9, 2025
An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a...
High
Unreviewed
CVE-2025-52322
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API