GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
838 advisories
Filter by severity
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an...
High
Unreviewed
CVE-2025-26436
was published
Sep 5, 2025
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with...
High
Unreviewed
CVE-2025-23256
was published
Sep 5, 2025
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without...
High
Unreviewed
CVE-2025-48523
was published
Sep 4, 2025
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due...
High
Unreviewed
CVE-2025-32333
was published
Sep 4, 2025
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to...
High
Unreviewed
CVE-2025-55177
was published
Aug 29, 2025
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their...
High
Unreviewed
CVE-2025-36120
was published
Aug 18, 2025
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web...
High
Unreviewed
CVE-2025-7773
was published
Aug 14, 2025
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and...
High
Unreviewed
CVE-2025-49556
was published
Aug 12, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
High
Unreviewed
CVE-2024-41979
was published
Aug 12, 2025
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain...
High
Unreviewed
CVE-2025-42951
was published
Aug 12, 2025
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without...
High
Unreviewed
CVE-2025-20701
was published
Aug 4, 2025
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux...
High
Unreviewed
CVE-2025-6018
was published
Jul 23, 2025
Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions...
High
Unreviewed
CVE-2025-30751
was published
Jul 15, 2025
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite ...
High
Unreviewed
CVE-2025-30743
was published
Jul 15, 2025
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2025-30744
was published
Jul 15, 2025
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect...
High
Unreviewed
CVE-2025-49536
was published
Jul 8, 2025
Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege...
High
Unreviewed
CVE-2025-5822
was published
Jun 26, 2025
Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to...
High
Unreviewed
CVE-2025-48466
was published
Jun 26, 2025
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of...
High
Unreviewed
CVE-2025-5071
was published
Jun 19, 2025
The ws.stash.app.mac.daemon.helper tool contains a vulnerability caused by an incorrect use of...
High
Unreviewed
CVE-2024-7457
was published
Jun 11, 2025
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V3.2),...
High
Unreviewed
CVE-2025-40567
was published
Jun 10, 2025
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an...
High
Unreviewed
CVE-2025-40669
was published
Jun 9, 2025
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker,...
High
Unreviewed
CVE-2025-40668
was published
Jun 9, 2025
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an...
High
Unreviewed
CVE-2025-40670
was published
Jun 9, 2025
Memory corruption due to unauthorized command execution in GPU micronode while executing specific...
High
Unreviewed
CVE-2025-21479
was published
Jun 3, 2025
ProTip!
Advisories are also available from the
GraphQL API