GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,555 advisories
Filter by severity
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to...
High
Unreviewed
CVE-2025-49692
was published
Sep 9, 2025
Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress...
High
Unreviewed
CVE-2025-48101
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55141
was published
Sep 9, 2025
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6,...
High
Unreviewed
CVE-2025-55147
was published
Sep 9, 2025
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 Security Update 1 and...
High
Unreviewed
CVE-2025-9712
was published
Sep 9, 2025
Improper Validation of Specified Quantity in Input vulnerability in ThemesGrove WP SmartPay. This...
High
Unreviewed
CVE-2025-32689
was published
Sep 9, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-47694
was published
Sep 9, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-47571
was published
Sep 9, 2025
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU)...
High
Unreviewed
CVE-2025-55317
was published
Sep 9, 2025
External control of file name or path in Azure Arc allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-55316
was published
Sep 9, 2025
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized...
High
Unreviewed
CVE-2025-55236
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-55223
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-55228
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54105
was published
Sep 9, 2025
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an...
High
Unreviewed
CVE-2025-54106
was published
Sep 9, 2025
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to...
High
Unreviewed
CVE-2025-53805
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55142
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55148
was published
Sep 9, 2025
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 Security Update 1 and...
High
Unreviewed
CVE-2025-9872
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55145
was published
Sep 9, 2025
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network...
High
Unreviewed
CVE-2025-20287
was published
Sep 9, 2025
In the Linux kernel, the following vulnerability has been resolved:
mm/khugepaged: fix -...
High
Unreviewed
CVE-2023-52935
was published
Mar 27, 2025
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could...
High
Unreviewed
CVE-2023-32701
was published
Nov 14, 2023
A code execution security issue exists in the affected product. An attacker with physical access...
High
Unreviewed
CVE-2025-9160
was published
Sep 9, 2025
A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and...
High
Unreviewed
CVE-2025-7350
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API