GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,005 advisories
Filter by severity
Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an...
Moderate
Unreviewed
CVE-2025-58135
was published
Sep 10, 2025
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'...
Moderate
Unreviewed
CVE-2025-9997
was published
Sep 10, 2025
Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon...
Moderate
Unreviewed
CVE-2025-58131
was published
Sep 10, 2025
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated...
Moderate
Unreviewed
CVE-2025-58134
was published
Sep 10, 2025
Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to...
Moderate
Unreviewed
CVE-2025-49461
was published
Sep 10, 2025
Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a...
Moderate
Unreviewed
CVE-2025-49458
was published
Sep 10, 2025
Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated...
Moderate
Unreviewed
CVE-2025-49460
was published
Sep 10, 2025
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-7746
was published
Sep 9, 2025
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'...
Moderate
Unreviewed
CVE-2025-9996
was published
Sep 9, 2025
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Moderate
Unreviewed
CVE-2025-55054
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_ip_reputation.php, the value of the iplist parameter is not...
Moderate
Unreviewed
CVE-2025-34176
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_flow_stream.php, the value of the policy_name parameter is not...
Moderate
Unreviewed
CVE-2025-34177
was published
Sep 9, 2025
Insecure Storage of Sensitive Information vulnerability in Calix GigaCenter ONT (Quantenna SoC...
Moderate
Unreviewed
CVE-2025-54083
was published
Sep 9, 2025
In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not...
Moderate
Unreviewed
CVE-2025-34178
was published
Sep 9, 2025
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read...
Moderate
Unreviewed
CVE-2025-54241
was published
Sep 9, 2025
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read...
Moderate
Unreviewed
CVE-2025-54240
was published
Sep 9, 2025
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read...
Moderate
Unreviewed
CVE-2025-54239
was published
Sep 9, 2025
IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2025-36011
was published
Sep 9, 2025
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross...
Moderate
Unreviewed
CVE-2025-36125
was published
Sep 9, 2025
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a...
Moderate
Unreviewed
CVE-2025-54255
was published
Sep 9, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-47415
was published
Sep 9, 2025
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP...
Moderate
Unreviewed
CVE-2025-43786
was published
Sep 9, 2025
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is...
Moderate
Unreviewed
CVE-2025-34174
was published
Sep 9, 2025
In pfSense CE /usr/local/www/suricata/suricata_filecheck.php, the value of the filehash parameter...
Moderate
Unreviewed
CVE-2025-34175
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API