GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
12,258 advisories
Filter by severity
Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members...
Low
Unreviewed
CVE-2025-8573
was published
Aug 6, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the...
Low
Unreviewed
CVE-2025-44964
was published
Aug 5, 2025
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects...
Low
Unreviewed
CVE-2025-8534
was published
Aug 5, 2025
The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP...
Low
Unreviewed
CVE-2025-4599
was published
Aug 5, 2025
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local...
Low
Unreviewed
CVE-2025-46094
was published
Aug 5, 2025
Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if...
Low
Unreviewed
CVE-2025-7844
was published
Aug 5, 2025
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4....
Low
Unreviewed
CVE-2025-8522
was published
Aug 4, 2025
A vulnerability was found in Intelbras InControl 2.21.60.9 and classified as problematic. This...
Low
Unreviewed
CVE-2025-8515
was published
Aug 4, 2025
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the...
Low
Unreviewed
CVE-2025-54956
was published
Aug 3, 2025
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit...
Low
Unreviewed
CVE-2025-54350
was published
Aug 3, 2025
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get...
Low
Unreviewed
CVE-2025-23290
was published
Aug 3, 2025
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may cause an...
Low
Unreviewed
CVE-2025-23288
was published
Aug 3, 2025
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access...
Low
Unreviewed
CVE-2025-23287
was published
Aug 3, 2025
A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected...
Low
Unreviewed
CVE-2024-13978
was published
Aug 2, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low
CVE-2025-6011
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes and...
Low
Unreviewed
CVE-2023-44976
was published
Aug 1, 2025
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server...
Low
Unreviewed
CVE-2023-32251
was published
Jul 31, 2025
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
Low
Unreviewed
CVE-2025-37108
was published
Jul 31, 2025
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
Low
Unreviewed
CVE-2025-37109
was published
Jul 31, 2025
Microweber Has Stored XSS Vulnerability in User Profile Fields
Low
CVE-2025-51503
was published
for
microweber/microweber
(Composer)
Jul 31, 2025
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the...
Low
Unreviewed
CVE-2025-51383
was published
Jul 31, 2025
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the...
Low
Unreviewed
CVE-2025-51384
was published
Jul 31, 2025
D-LINK DI-8200 16.07.26A1 is vulnerable to Buffer Overflow in the yyxz_dlink_asp function via the...
Low
Unreviewed
CVE-2025-51385
was published
Jul 31, 2025
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
Low
CVE-2025-53011
was published
for
MaterialX
(pip)
Jul 31, 2025
ProTip!
Advisories are also available from the
GraphQL API