GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
287,846 advisories
Filter by severity
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-8224
was published
Jul 27, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-8227
was published
Jul 27, 2025
Google gVisor's runsc component exhibited a local privilege escalation vulnerability due to...
Moderate
Unreviewed
CVE-2025-2713
was published
Mar 28, 2025
A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close...
High
Unreviewed
CVE-2023-32256
was published
Aug 1, 2025
IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a...
High
Unreviewed
CVE-2025-2824
was published
Aug 1, 2025
A SQL Injection vulnerability exists in the takeassessment2.php file of CloudClassroom-PHP...
Moderate
Unreviewed
CVE-2025-50868
was published
Aug 1, 2025
A stored Cross-Site Scripting (XSS) vulnerability exists in the qureydetails.php page of...
Moderate
Unreviewed
CVE-2025-50869
was published
Aug 1, 2025
Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0...
Unknown
Unreviewed
CVE-2025-52361
was published
Aug 1, 2025
Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection...
Critical
Unreviewed
CVE-2025-52390
was published
Aug 1, 2025
IBM QRadar SIEM 7.5 through 7.5.0 Update Pack 12 is vulnerable to stored cross-site scripting....
Moderate
Unreviewed
CVE-2025-33118
was published
Aug 1, 2025
Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network...
High
Unreviewed
CVE-2025-8480
was published
Aug 1, 2025
Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-8473
was published
Aug 1, 2025
Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-8472
was published
Aug 1, 2025
Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-8475
was published
Aug 1, 2025
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2025-8476
was published
Aug 1, 2025
Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This...
Moderate
Unreviewed
CVE-2025-8474
was published
Aug 1, 2025
Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-8477
was published
Aug 1, 2025
SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain...
Unknown
Unreviewed
CVE-2025-52327
was published
Aug 1, 2025
A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0...
Moderate
Unreviewed
CVE-2025-45778
was published
Aug 1, 2025
The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through...
Critical
Unreviewed
CVE-2025-50472
was published
Aug 1, 2025
Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog...
Unknown
Unreviewed
CVE-2025-44139
was published
Aug 1, 2025
Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view...
Critical
Unreviewed
CVE-2025-45150
was published
Aug 1, 2025
XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304)...
Unknown
Unreviewed
CVE-2019-19144
was published
Aug 1, 2025
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated...
Moderate
Unreviewed
CVE-2025-3277
was published
Apr 14, 2025
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of...
Moderate
Unreviewed
CVE-2021-1440
was published
Nov 18, 2024
ProTip!
Advisories are also available from the
GraphQL API