GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
165 advisories
Filter by severity
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for...
High
Unreviewed
CVE-2025-36222
was published
Sep 11, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept...
Moderate
Unreviewed
CVE-2025-32330
was published
Sep 4, 2025
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the...
High
Unreviewed
CVE-2024-6788
was published
Aug 13, 2024
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation...
Critical
Unreviewed
CVE-2025-7353
was published
Aug 14, 2025
A vulnerability has been identified in RUGGEDCOM ROS for RSL910 devices (All versions < ROS V5.0...
High
Unreviewed
CVE-2017-12736
was published
May 13, 2022
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk...
High
Unreviewed
CVE-2025-44647
was published
Jul 21, 2025
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
Moderate
CVE-2024-26267
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure...
High
Unreviewed
CVE-2025-25271
was published
Jul 8, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain...
Critical
Unreviewed
CVE-2025-41672
was published
Jul 7, 2025
Insecure Default Initialization of Resource vulnerability in Apache Solr
High
CVE-2024-45217
was published
for
org.apache.solr:solr
(Maven)
Oct 16, 2024
The Versa Director software exposes a number of services by default and allow attackers an easy...
Critical
Unreviewed
CVE-2025-24288
was published
Jun 19, 2025
The CS5000 Fire Panel is vulnerable due to a default account that exists
on the panel. Even...
Critical
Unreviewed
CVE-2025-41438
was published
May 30, 2025
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap...
Moderate
Unreviewed
CVE-2025-48927
was published
May 28, 2025
A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All...
High
Unreviewed
CVE-2025-31930
was published
May 13, 2025
In the Linux kernel, the following vulnerability has been resolved:
dm btree remove: assign...
Moderate
Unreviewed
CVE-2021-47343
was published
May 21, 2024
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an...
Moderate
Unreviewed
CVE-2023-48733
was published
Feb 15, 2024
CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate
CVE-2025-46599
was published
for
github.com/k3s-io/k3s
(Go)
Apr 25, 2025
Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before...
Moderate
Unreviewed
CVE-2021-33130
was published
May 13, 2022
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
High
Unreviewed
CVE-2025-43015
was published
Apr 17, 2025
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier....
High
Unreviewed
CVE-2017-5155
was published
May 13, 2022
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in...
Critical
Unreviewed
CVE-2017-5178
was published
May 13, 2022
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting...
Moderate
Unreviewed
CVE-2017-5491
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API