GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
13 advisories
Filter by severity
Some "Stored Value" Unattended Payment Solutions of KioSoft use vulnerable NFC cards. Attackers...
Critical
Unreviewed
CVE-2025-8699
was published
Sep 12, 2025
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in...
Critical
Unreviewed
CVE-2025-24109
was published
Jan 28, 2025
Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what...
Critical
Unreviewed
CVE-2024-4995
was published
Dec 18, 2024
InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx...
Critical
Unreviewed
CVE-2024-30896
was published
Nov 27, 2024
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3502
was published
Nov 14, 2024
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3501
was published
Nov 14, 2024
An
authentication bypass vulnerability exists in the affected product. The
vulnerability exists...
Critical
Unreviewed
CVE-2024-10943
was published
Nov 12, 2024
rke's credentials are stored in the RKE1 Cluster state ConfigMap
Critical
CVE-2023-32191
was published
for
github.com/rancher/rke
(Go)
Jun 17, 2024
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed...
Critical
Unreviewed
CVE-2023-29727
was published
May 31, 2023
Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise)...
Critical
Unreviewed
CVE-2023-0580
was published
Apr 6, 2023
lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
Critical
Unreviewed
CVE-2021-42371
was published
May 24, 2022
An issue was discovered on FiberHome HG6245D devices through RP2613. By default, there are no...
Critical
Unreviewed
CVE-2021-27170
was published
May 24, 2022
Remote code execution in Apache Tapestry
Critical
CVE-2021-27850
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Jun 16, 2021
ProTip!
Advisories are also available from the
GraphQL API