GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
82 advisories
Filter by severity
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The...
High
Unreviewed
CVE-2024-32011
was published
Nov 11, 2025
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that...
High
Unreviewed
CVE-2021-41841
was published
Feb 10, 2022
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the...
High
Unreviewed
CVE-2021-33626
was published
May 24, 2022
An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co....
High
Unreviewed
CVE-2025-41390
was published
Oct 20, 2025
On a client with an admin user, a Global_Shipping script can be implemented. The script could...
High
Unreviewed
CVE-2025-12509
was published
Oct 31, 2025
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
High
CVE-2025-62726
was published
for
n8n
(npm)
Oct 30, 2025
Kedro allows Remote Code Execution by Pulling Micro Packages
High
CVE-2024-12215
was published
for
kedro
(pip)
Mar 20, 2025
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11...
High
Unreviewed
CVE-2025-36355
was published
Oct 6, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49133
was published
Apr 9, 2024
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49134
was published
Apr 9, 2024
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin...
High
Unreviewed
CVE-2025-8714
was published
Aug 14, 2025
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue...
High
Unreviewed
CVE-2025-36727
was published
Jul 25, 2025
The Secure Password extension in One Identity Password Manager before 5.14.4 allows local...
High
Unreviewed
CVE-2025-27582
was published
Jul 14, 2025
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by...
High
Unreviewed
CVE-2025-49809
was published
Jul 4, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-39507
was published
May 16, 2025
Markdownify subject to Remote Code Execution via malicious markdown file
High
CVE-2022-41709
was published
for
electron-markdownify
(npm)
Oct 19, 2022
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated,...
High
Unreviewed
CVE-2025-20236
was published
Apr 16, 2025
An iframe that was not permitted to run scripts could do so if the user clicked on a <code...
High
Unreviewed
CVE-2022-34468
was published
Dec 22, 2022
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B...
High
Unreviewed
CVE-2024-45482
was published
Mar 25, 2025
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin...
High
Unreviewed
CVE-2024-13353
was published
Feb 21, 2025
Apache HDFS Provider error message suggested
High
CVE-2023-41267
was published
for
apache-airflow-providers-apache-hdfs
(pip)
Sep 14, 2023
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
High
CVE-2024-28184
was published
for
weasyprint
(pip)
Mar 8, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53800
was published
Jan 7, 2025
ProTip!
Advisories are also available from the
GraphQL API