GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,563 advisories
Filter by severity
A denial-of-service security issue exists in the affected product and version. The security issue...
High
Unreviewed
CVE-2025-9166
was published
Sep 9, 2025
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization....
High
Unreviewed
CVE-2025-9161
was published
Sep 9, 2025
A code execution security issue exists in the affected product. An attacker with physical access...
High
Unreviewed
CVE-2025-9160
was published
Sep 9, 2025
A server-side request forgery security issue exists within Rockwell Automation ThinManager®...
High
Unreviewed
CVE-2025-9065
was published
Sep 9, 2025
A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and...
High
Unreviewed
CVE-2025-7350
was published
Sep 9, 2025
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of...
High
Unreviewed
CVE-2025-7970
was published
Sep 9, 2025
A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules,...
High
Unreviewed
CVE-2025-8007
was published
Sep 9, 2025
A security issue exists in the protected mode of EN4TR devices, where sending specifically...
High
Unreviewed
CVE-2025-8008
was published
Sep 9, 2025
toodee is vulnerable to Heap Buffer Overflow through its DrainCol Destructor
High
GHSA-pfp7-vxgr-83pw
was published
for
toodee
(Rust)
Sep 9, 2025
DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware
High
CVE-2025-59037
was published
for
@duckdb/duckdb-wasm
(npm)
Sep 9, 2025
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.
...
High
Unreviewed
CVE-2025-24404
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')...
High
Unreviewed
CVE-2025-48208
was published
Sep 9, 2025
TYPO3 Workspaces Module Information Disclosure
High
CVE-2025-59018
was published
for
typo3/cms-workspaces
(Composer)
Sep 9, 2025
An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a...
High
Unreviewed
CVE-2025-41701
was published
Sep 9, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 ...
High
Unreviewed
CVE-2025-40798
was published
Sep 9, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 ...
High
Unreviewed
CVE-2025-40796
was published
Sep 9, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 ...
High
Unreviewed
CVE-2025-40797
was published
Sep 9, 2025
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in...
High
Unreviewed
CVE-2025-9539
was published
Sep 9, 2025
When a user logs in via SAP Business One native client, the SLD backend service fails to enforce...
High
Unreviewed
CVE-2025-42933
was published
Sep 9, 2025
Due to missing input validation, an attacker with high privilege access to ABAP reports could...
High
Unreviewed
CVE-2025-42929
was published
Sep 9, 2025
Due to missing input validation, an attacker with high privilege access to ABAP reports could...
High
Unreviewed
CVE-2025-42916
was published
Sep 9, 2025
A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the...
High
Unreviewed
CVE-2025-10120
was published
Sep 9, 2025
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and...
High
Unreviewed
CVE-2025-55849
was published
Sep 8, 2025
Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the...
High
Unreviewed
CVE-2025-52288
was published
Sep 8, 2025
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4...
High
Unreviewed
CVE-2025-52389
was published
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API