GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
37 advisories
Filter by severity
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control...
Critical
Unreviewed
CVE-2025-59033
was published
Sep 8, 2025
Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure...
Critical
Unreviewed
CVE-2025-43728
was published
Aug 27, 2025
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the...
Critical
Unreviewed
CVE-2025-54143
was published
Aug 19, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6,...
Critical
Unreviewed
CVE-2025-43261
was published
Jul 30, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
Critical
Unreviewed
CVE-2025-43273
was published
Jul 30, 2025
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by...
Critical
Unreviewed
CVE-2025-6427
was published
Jun 26, 2025
Spring Security authorization bypass for method security annotations on private methods
Critical
CVE-2025-41232
was published
for
org.springframework.security:spring-security-aspects
(Maven)
May 21, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27665
was published
Mar 5, 2025
Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when...
Critical
Unreviewed
CVE-2024-25091
was published
Mar 1, 2024
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful...
Critical
Unreviewed
CVE-2023-52378
was published
Feb 18, 2024
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an...
Critical
Unreviewed
CVE-2023-31273
was published
Nov 14, 2023
Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An...
Critical
Unreviewed
CVE-2023-32493
was published
Aug 16, 2023
Microsoft Office Security Feature Bypass Vulnerability
Critical
Unreviewed
CVE-2023-33150
was published
Jul 11, 2023
Sandbox escape in Jenkins Email Extension Plugin
Critical
CVE-2023-25765
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
Feb 15, 2023
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of...
Critical
Unreviewed
CVE-2022-48290
was published
Feb 9, 2023
An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is...
Critical
Unreviewed
CVE-2022-47544
was published
Jan 5, 2023
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code>...
Critical
Unreviewed
CVE-2022-26384
was published
Dec 22, 2022
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently...
Critical
Unreviewed
CVE-2022-22759
was published
Dec 22, 2022
User login brute force protection functionality bypass
Critical
Unreviewed
CVE-2022-27516
was published
Nov 9, 2022
Jenkins Script Security Plugin sandbox bypass vulnerability
Critical
CVE-2022-43403
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
Oct 19, 2022
Jenkins Pipeline: Groovy Plugin allows sandbox protection bypass and arbitrary code execution
Critical
CVE-2022-43402
was published
for
org.jenkins-ci.plugins.workflow:workflow-cps
(Maven)
Oct 19, 2022
isolated-vm has vulnerable CachedDataOptions in API
Critical
CVE-2022-39266
was published
for
isolated-vm
(npm)
Sep 30, 2022
This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and...
Critical
Unreviewed
CVE-2022-32845
was published
Sep 25, 2022
An unauthenticated attacker can update the hostname with a specially crafted name that will allow...
Critical
Unreviewed
CVE-2022-31479
was published
Jun 7, 2022
Unsafe entry in Script Security list of approved signatures in Pipeline Remote Loader Plugin
Critical
CVE-2019-10328
was published
for
org.jenkins-ci.plugins:workflow-remote-loader
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API