GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
11,458 advisories
Filter by severity
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via...
High
Unreviewed
CVE-2025-56404
was published
Sep 10, 2025
A security flaw has been discovered in lmsys sglang 0.4.6. Affected by this vulnerability is the...
Moderate
Unreviewed
CVE-2025-10164
was published
Sep 9, 2025
TinyEnv: Inline comments not stripped properly in .env values
Moderate
CVE-2025-58759
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
High
Unreviewed
CVE-2025-54248
was published
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-54247
was published
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-54250
was published
Sep 9, 2025
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an...
Moderate
Unreviewed
CVE-2025-53809
was published
Sep 9, 2025
Apache DolphinScheduler vulnerable to Alert Script Attack
High
CVE-2024-43115
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 9, 2025
Magento Community Edition Improper Input Validation vulnerability
Critical
CVE-2025-54236
was published
for
magento/community-edition
(Composer)
Sep 9, 2025
A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules,...
High
Unreviewed
CVE-2025-8007
was published
Sep 9, 2025
Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow...
High
Unreviewed
CVE-2024-36342
was published
Sep 6, 2025
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker...
High
Unreviewed
CVE-2024-36354
was published
Sep 6, 2025
Improper input validation in the system management mode (SMM) could allow a privileged attacker...
High
Unreviewed
CVE-2024-21947
was published
Sep 6, 2025
An authorized user can cause a crash in the MongoDB Server through a specially crafted $group...
Moderate
Unreviewed
CVE-2025-10061
was published
Sep 5, 2025
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1...
Moderate
Unreviewed
CVE-2023-21472
was published
Sep 5, 2025
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1...
Moderate
Unreviewed
CVE-2023-21473
was published
Sep 5, 2025
In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a...
High
Unreviewed
CVE-2025-32322
was published
Sep 4, 2025
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to...
Moderate
Unreviewed
CVE-2025-48538
was published
Sep 4, 2025
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops...
Moderate
Unreviewed
CVE-2025-48559
was published
Sep 4, 2025
In multiple methods of NotificationChannel.java, there is a possible desynchronization from...
High
Unreviewed
CVE-2025-48556
was published
Sep 4, 2025
In multiple locations, there is a possible way to persistently DoS the device due to improper...
High
Unreviewed
CVE-2025-48537
was published
Sep 4, 2025
In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user...
High
Unreviewed
CVE-2025-48541
was published
Sep 4, 2025
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to...
Moderate
Unreviewed
CVE-2025-26429
was published
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API