GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
28 advisories
Filter by severity
Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information...
Moderate
Unreviewed
CVE-2025-5823
was published
Jun 26, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site
Moderate
CVE-2025-30359
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
A USB backdoor feature can be triggered by attaching a USB drive that contains specially crafted ...
Moderate
Unreviewed
CVE-2025-48415
was published
May 21, 2025
SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not...
Moderate
Unreviewed
CVE-2025-43003
was published
May 13, 2025
Exposed dangerous method or function in Windows Local Session Manager (LSM) allows an authorized...
Moderate
Unreviewed
CVE-2025-26651
was published
Apr 8, 2025
H2O Vulnerable to Execution of Arbitrary Files
Moderate
CVE-2024-6863
was published
for
ai.h2o:h2o-core
(Maven)
Mar 20, 2025
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
Moderate
CVE-2025-24361
was published
for
@nuxt/rspack-builder
(npm)
Jan 27, 2025
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Indexed Search Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55923
was published
for
typo3/cms-indexed-search
(Composer)
Jan 14, 2025
TYPO3 Form Framework Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55922
was published
for
typo3/cms-form
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Dashboard Module
Moderate
CVE-2024-55920
was published
for
typo3/cms-dashboard
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
Orchid Platform has Method Exposure Vulnerability in Modals
Moderate
CVE-2024-51992
was published
for
orchid/platform
(Composer)
Nov 12, 2024
The lack of access restriction to a resource from unauthorized users makes MXsecurity software...
Moderate
Unreviewed
CVE-2024-4739
was published
Oct 18, 2024
Default installation of `synthetic-monitoring-agent` exposes sensitive information
Moderate
CVE-2022-46156
was published
for
github.com/grafana/synthetic-monitoring-agent
(Go)
Sep 6, 2024
PDF-XChange Editor Net.HTTP.requests Exposed Dangerous Function Information Disclosure...
Moderate
Unreviewed
CVE-2023-39505
was published
May 3, 2024
PDF-XChange Editor readFileIntoStream Exposed Dangerous Function Information Disclosure...
Moderate
Unreviewed
CVE-2023-39495
was published
May 3, 2024
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to...
Moderate
Unreviewed
CVE-2024-27261
was published
Apr 12, 2024
In JetBrains TeamCity before 2023.11 users with access to the agent machine might obtain...
Moderate
Unreviewed
CVE-2024-29880
was published
Mar 21, 2024
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050...
Moderate
Unreviewed
CVE-2023-33921
was published
Jun 13, 2023
xwiki contains Exposed Dangerous Method or Function
Moderate
CVE-2023-26478
was published
for
org.xwiki.platform:xwiki-platform-store-filesystem-oldcore
(Maven)
Mar 3, 2023
A user authorized to perform database queries may trigger denial of service by issuing specially...
Moderate
Unreviewed
CVE-2019-20923
was published
May 24, 2022
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an...
Moderate
Unreviewed
CVE-2019-4386
was published
May 24, 2022
An issue was discovered in app/Model/Attribute.php in MISP before 2.4.89. There is a critical API...
Moderate
Unreviewed
CVE-2018-8949
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API