GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,855 advisories
Filter by severity
Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer...
Critical
Unreviewed
CVE-2010-20122
was published
Aug 21, 2025
EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its...
Critical
Unreviewed
CVE-2010-20113
was published
Aug 21, 2025
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2025-53795
was published
Aug 21, 2025
Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by...
Critical
Unreviewed
CVE-2010-20112
was published
Aug 21, 2025
A remote unauthenticated attacker who has bypassed authentication could
execute arbitrary OS...
Critical
Unreviewed
CVE-2025-3128
was published
Aug 21, 2025
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2025-53763
was published
Aug 21, 2025
EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the...
Critical
Unreviewed
CVE-2010-20121
was published
Aug 21, 2025
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user...
Critical
Unreviewed
CVE-2025-52352
was published
Aug 21, 2025
An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8...
Critical
Unreviewed
CVE-2024-45438
was published
Aug 21, 2025
An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2025-52395
was published
Aug 21, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP allows Upload a...
Critical
Unreviewed
CVE-2025-53251
was published
Aug 21, 2025
Plex Media Server (PMS) versions 1.41.7.x through 1.42.0.x are affected by an unspecified...
Critical
Unreviewed
CVE-2025-34158
was published
Aug 21, 2025
sha.js is missing type checks leading to hash rewind and passing on crafted data
Critical
CVE-2025-9288
was published
for
sha.js
(npm)
Aug 21, 2025
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
Critical
CVE-2025-9287
was published
for
cipher-base
(npm)
Aug 21, 2025
The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing...
Critical
Unreviewed
CVE-2025-8895
was published
Aug 21, 2025
A malicious client can bypass the client certificate trust check of an opc.https server when the...
Critical
Unreviewed
CVE-2025-7390
was published
Aug 21, 2025
A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro...
Critical
Unreviewed
CVE-2025-27214
was published
Aug 21, 2025
A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with...
Critical
Unreviewed
CVE-2025-27217
was published
Aug 21, 2025
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a...
Critical
Unreviewed
CVE-2025-24285
was published
Aug 21, 2025
Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access...
Critical
Unreviewed
CVE-2024-57155
was published
Aug 20, 2025
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical
CVE-2025-54988
was published
for
org.apache.tika:tika-parser-pdf-module
(Maven)
Aug 20, 2025
Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication...
Critical
Unreviewed
CVE-2024-57154
was published
Aug 20, 2025
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
Critical
CVE-2025-55746
was published
for
@directus/api
(npm)
Aug 20, 2025
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution...
Critical
Unreviewed
CVE-2025-8611
was published
Aug 20, 2025
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution...
Critical
Unreviewed
CVE-2025-8610
was published
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API