GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,548 advisories
Filter by severity
mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders
Moderate
CVE-2025-59940
was published
for
mkdocs-include-markdown-plugin
(pip)
Sep 29, 2025
A vulnerability was detected in pmTicket Project-Management-Software up to...
Moderate
Unreviewed
CVE-2025-11135
was published
Sep 29, 2025
A vulnerability has been found in giantspatula SewKinect up to...
Moderate
Unreviewed
CVE-2025-10974
was published
Sep 26, 2025
A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997....
Moderate
Unreviewed
CVE-2025-10975
was published
Sep 26, 2025
A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue...
Moderate
Unreviewed
CVE-2025-10965
was published
Sep 25, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
Ericsson
Indoor Connect 8855 contains an improper input validation vulnerability which if...
High
Unreviewed
CVE-2025-40836
was published
Sep 25, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
Llama Stack could potentially allow for remote code execution
Moderate
CVE-2025-55178
was published
for
llama-stack
(pip)
Sep 24, 2025
Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File...
High
Unreviewed
CVE-2025-52907
was published
Sep 24, 2025
Memory corruption while processing data sent by FE driver.
High
Unreviewed
CVE-2025-47314
was published
Sep 24, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects...
High
Unreviewed
CVE-2025-52905
was published
Sep 23, 2025
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-10770
was published
Sep 22, 2025
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-10771
was published
Sep 22, 2025
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script...
Critical
Unreviewed
CVE-2025-57644
was published
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
Moderate
CVE-2025-59535
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-10769
was published
Sep 22, 2025
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function...
Moderate
Unreviewed
CVE-2025-10768
was published
Sep 22, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
CVE-2025-59532
was published
for
@openai/codex
(npm)
Sep 19, 2025
Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension...
Moderate
Unreviewed
CVE-2025-58114
was published
Sep 19, 2025
An issue was discovered in Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01 allowing attackers to...
High
Unreviewed
CVE-2025-57528
was published
Sep 19, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker...
Moderate
Unreviewed
CVE-2025-23336
was published
Sep 18, 2025
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may...
High
Unreviewed
CVE-2025-23268
was published
Sep 18, 2025
ProTip!
Advisories are also available from the
GraphQL API