GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,489
Maven
5,000+
npm
4,106
NuGet
735
pip
3,928
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
10,879 advisories
Filter by severity
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly...
Low
Unreviewed
CVE-2025-8277
was published
Sep 9, 2025
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The...
Low
Unreviewed
CVE-2025-40803
was published
Sep 9, 2025
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The...
Low
Unreviewed
CVE-2025-40802
was published
Sep 9, 2025
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable...
Low
Unreviewed
CVE-2025-42927
was published
Sep 9, 2025
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an...
Low
Unreviewed
CVE-2025-42914
was published
Sep 9, 2025
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an...
Low
Unreviewed
CVE-2025-42913
was published
Sep 9, 2025
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay...
Low
Unreviewed
CVE-2025-43774
was published
Sep 9, 2025
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the...
Low
Unreviewed
CVE-2024-48341
was published
Sep 8, 2025
PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023...
Low
Unreviewed
CVE-2023-21466
was published
Sep 8, 2025
A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue...
Low
Unreviewed
CVE-2025-10080
was published
Sep 8, 2025
RICOH Streamline NX versions 3.5.1 to 24R3 are vulnerable to tampering with operation history. If...
Low
Unreviewed
CVE-2025-58422
was published
Sep 8, 2025
Improper removal of sensitive information before storage or transfer in AMD Crash Defender could...
Low
Unreviewed
CVE-2025-0011
was published
Sep 6, 2025
Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor...
Low
Unreviewed
CVE-2024-36331
was published
Sep 6, 2025
An out-of-bounds read in the ASP could allow a privileged attacker with access to a malicious...
Low
Unreviewed
CVE-2023-31330
was published
Sep 6, 2025
An integer overflow in the SMU could allow a privileged attacker to potentially write memory...
Low
Unreviewed
CVE-2023-31365
was published
Sep 6, 2025
Failure to validate the address and size in TEE (Trusted Execution Environment) may allow a...
Low
Unreviewed
CVE-2021-46750
was published
Sep 6, 2025
Improper handling of insufficiency privileges in the ASP could allow a privileged attacker to...
Low
Unreviewed
CVE-2023-20516
was published
Sep 6, 2025
Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from...
Low
Unreviewed
CVE-2023-31326
was published
Sep 6, 2025
Improper validation of an array index in the AMD graphics driver software could allow an attacker...
Low
Unreviewed
CVE-2023-31306
was published
Sep 6, 2025
A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous...
Low
Unreviewed
CVE-2025-10043
was published
Sep 5, 2025
A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of...
Low
Unreviewed
CVE-2025-9725
was published
Sep 5, 2025
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a...
Low
Unreviewed
CVE-2025-30200
was published
Sep 5, 2025
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a...
Low
Unreviewed
CVE-2025-30198
was published
Sep 5, 2025
In Permission Manager, there is a possible way for the microphone privacy indicator to remain...
Low
Unreviewed
CVE-2025-26461
was published
Sep 5, 2025
A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of...
Low
Unreviewed
CVE-2025-10014
was published
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API