GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,550 advisories
Filter by severity
External control of file name or path in Azure Arc allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-55316
was published
Sep 9, 2025
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized...
High
Unreviewed
CVE-2025-55236
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-55223
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-55228
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54105
was published
Sep 9, 2025
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an...
High
Unreviewed
CVE-2025-54106
was published
Sep 9, 2025
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-53805
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55142
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55148
was published
Sep 9, 2025
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 Security Update 1 and...
High
Unreviewed
CVE-2025-9872
was published
Sep 9, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
High
Unreviewed
CVE-2025-20287
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55145
was published
Sep 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
mm/khugepaged: fix -...
High
Unreviewed
CVE-2023-52935
was published
Mar 27, 2025
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could...
High
Unreviewed
CVE-2023-32701
was published
Nov 14, 2023
A code execution security issue exists in the affected product. An attacker with physical access...
High
Unreviewed
CVE-2025-9160
was published
Sep 9, 2025
A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and...
High
Unreviewed
CVE-2025-7350
was published
Sep 9, 2025
A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules,...
High
Unreviewed
CVE-2025-8007
was published
Sep 9, 2025
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization....
High
Unreviewed
CVE-2025-9161
was published
Sep 9, 2025
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of...
High
Unreviewed
CVE-2025-7970
was published
Sep 9, 2025
A denial-of-service security issue exists in the affected product and version. The security issue...
High
Unreviewed
CVE-2025-9166
was published
Sep 9, 2025
A server-side request forgery security issue exists within Rockwell Automation ThinManager®...
High
Unreviewed
CVE-2025-9065
was published
Sep 9, 2025
A security issue exists in the protected mode of EN4TR devices, where sending specifically...
High
Unreviewed
CVE-2025-8008
was published
Sep 9, 2025
APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where...
High
Unreviewed
CVE-2025-33045
was published
Sep 9, 2025
An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows...
High
Unreviewed
CVE-2025-34520
was published
Aug 28, 2025
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local...
High
Unreviewed
CVE-2025-49156
was published
Jun 17, 2025
ProTip!
Advisories are also available from the
GraphQL API