GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,831
Erlang
36
GitHub Actions
33
Go
2,451
Maven
5,000+
npm
4,073
NuGet
723
pip
3,868
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
12,318 advisories
Filter by severity
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release...
Low
Unreviewed
CVE-2025-24925
was published
Aug 11, 2025
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web...
Low
Unreviewed
CVE-2025-52136
was published
Aug 10, 2025
A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic....
Low
Unreviewed
CVE-2025-8774
was published
Aug 9, 2025
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has...
Low
Unreviewed
CVE-2025-8751
was published
Aug 9, 2025
Apache Tomcat - CGI security constraint bypass
Low
CVE-2025-46701
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 29, 2025
Apache Tomcat Rewrite rule bypass
Low
CVE-2025-31651
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This...
Low
Unreviewed
CVE-2025-8708
was published
Aug 8, 2025
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
Low
CVE-2024-5798
was published
for
github.com/hashicorp/vault
(Go)
Jun 12, 2024
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25...
Low
Unreviewed
CVE-2024-56339
was published
Aug 7, 2025
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors
Low
GHSA-vh9x-phq6-fx54
was published
for
github.com/rs/cors
(Go)
Aug 6, 2025
•
withdrawn
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17...
Low
Unreviewed
CVE-2024-5528
was published
Feb 5, 2025
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive...
Low
Unreviewed
CVE-2025-38746
was published
Aug 6, 2025
CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
CVE-2025-8556
was published
for
github.com/cloudflare/circl
(Go)
Jun 10, 2025
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
GHSA-522r-9946-fw43
was published
for
github.com/cloudflare/circl
(Go)
Aug 6, 2025
•
withdrawn
Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Low
CVE-2025-8573
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local...
Low
Unreviewed
CVE-2025-21024
was published
Aug 6, 2025
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local...
Low
Unreviewed
CVE-2025-21023
was published
Aug 6, 2025
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local...
Low
Unreviewed
CVE-2025-21022
was published
Aug 6, 2025
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the...
Low
Unreviewed
CVE-2025-44964
was published
Aug 5, 2025
Memory handling issue in editcap could cause denial of service via crafted capture file
Low
Unreviewed
CVE-2024-4853
was published
May 14, 2024
Koa Open Redirect via Referrer Header (User-Controlled)
Low
CVE-2025-8129
was published
for
koa
(npm)
Jul 29, 2025
ProTip!
Advisories are also available from the
GraphQL API