GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,489
Maven
5,000+
npm
4,106
NuGet
735
pip
3,928
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,440 advisories
Filter by severity
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-58215
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-59008
was published
Sep 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle...
High
Unreviewed
CVE-2025-58991
was published
Sep 9, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-58993
was published
Sep 9, 2025
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
High
Unreviewed
CVE-2025-54916
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54913
was published
Sep 9, 2025
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who...
High
Unreviewed
CVE-2025-55234
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-55224
was published
Sep 9, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an...
High
Unreviewed
CVE-2025-55243
was published
Sep 9, 2025
Improper neutralization of special elements used in a command ('command injection') in SQL Server...
High
Unreviewed
CVE-2025-55227
was published
Sep 9, 2025
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over...
High
Unreviewed
CVE-2025-54918
was published
Sep 9, 2025
Improper link resolution before file access ('link following') in Xbox allows an authorized...
High
Unreviewed
CVE-2025-55245
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54919
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54115
was published
Sep 9, 2025
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute...
High
Unreviewed
CVE-2025-54906
was published
Sep 9, 2025
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2025-54908
was published
Sep 9, 2025
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code...
High
Unreviewed
CVE-2025-54898
was published
Sep 9, 2025
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
High
Unreviewed
CVE-2025-54912
was published
Sep 9, 2025
Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54112
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54114
was published
Sep 9, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-54903
was published
Sep 9, 2025
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
High
Unreviewed
CVE-2025-54904
was published
Sep 9, 2025
Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-53801
was published
Sep 9, 2025
Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54111
was published
Sep 9, 2025
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to...
High
Unreviewed
CVE-2025-54897
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API