GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary...
Moderate
Unreviewed
CVE-2025-62186
was published
Oct 7, 2025
DNN allows loading unused themes on anonymous clients through query parameters
Moderate
CVE-2025-59535
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic...
Moderate
Unreviewed
CVE-2025-57729
was published
Aug 20, 2025
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or -...
Moderate
Unreviewed
CVE-2025-54558
was published
Jul 25, 2025
A flaw was found in Yelp. The Gnome user help application allows the help document to execute...
Moderate
Unreviewed
CVE-2025-3155
was published
Apr 3, 2025
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd...
Moderate
Unreviewed
CVE-2024-52976
was published
May 1, 2025
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This...
Moderate
Unreviewed
CVE-2025-33027
was published
Apr 15, 2025
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-33026
was published
Apr 15, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-56216
was published
Dec 31, 2024
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel,...
Moderate
Unreviewed
CVE-2024-4359
was published
Aug 12, 2024
Improper Locking in JetBrains Kotlin
Moderate
CVE-2022-24329
was published
for
org.jetbrains.kotlin:kotlin-stdlib
(Maven)
Feb 26, 2022
Anki Latex Incomplete Blocklist Vulnerability
Moderate
CVE-2024-29073
was published
for
anki
(pip)
Jul 22, 2024
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access...
Moderate
Unreviewed
CVE-2024-5693
was published
Jun 11, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-35650
was published
Jun 10, 2024
Moderate severity vulnerability that affects org.springframework:spring-core
Moderate
CVE-2018-11040
was published
for
org.springframework:spring-core
(Maven)
Oct 16, 2018
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer...
Moderate
Unreviewed
CVE-2023-31170
was published
Aug 31, 2023
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the Schweitzer...
Moderate
Unreviewed
CVE-2023-31168
was published
Aug 31, 2023
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace...
Moderate
Unreviewed
CVE-2019-16951
was published
May 24, 2022
A same-origin policy violation occurs allowing the theft of cross-origin images through a...
Moderate
Unreviewed
CVE-2019-11742
was published
May 24, 2022
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1...
Moderate
Unreviewed
CVE-2023-21440
was published
Feb 9, 2023
IBM Content Navigator 3.0CD is vulnerable to local file inclusion, allowing an attacker to access...
Moderate
Unreviewed
CVE-2019-4263
was published
May 24, 2022
Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4
Moderate
CVE-2021-26272
was published
for
ckeditor4
(npm)
Oct 13, 2021
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow...
Moderate
Unreviewed
CVE-2018-8351
was published
May 13, 2022
Command Injection in @theia/messages
Moderate
CVE-2021-28162
was published
for
@theia/messages
(npm)
May 10, 2021
ProTip!
Advisories are also available from the
GraphQL API