GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,305 advisories
Filter by severity
In executeAppFunction of AppSearchManagerService.java, there is a possible background activity...
High
Unreviewed
CVE-2025-26464
was published
Sep 4, 2025
In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning...
High
Unreviewed
CVE-2025-32331
was published
Sep 4, 2025
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a...
High
Unreviewed
CVE-2025-32345
was published
Sep 4, 2025
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file...
High
Unreviewed
CVE-2025-32323
was published
Sep 4, 2025
In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to...
High
Unreviewed
CVE-2025-26454
was published
Sep 4, 2025
In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP...
High
Unreviewed
CVE-2025-26438
was published
Sep 4, 2025
In multiple locations, there is a possible memory corruption due to a use after free. This could...
High
Unreviewed
CVE-2025-32332
was published
Sep 4, 2025
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due...
High
Unreviewed
CVE-2025-32333
was published
Sep 4, 2025
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent...
High
Unreviewed
CVE-2025-32326
was published
Sep 4, 2025
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch...
High
Unreviewed
CVE-2025-32324
was published
Sep 4, 2025
In appendFrom of Parcel.cpp, there is a possible out of bounds write due to a heap buffer...
High
Unreviewed
CVE-2025-32325
was published
Sep 4, 2025
In multiple functions of PickerDbFacade.java, there is a possible unauthorized data access due to...
High
Unreviewed
CVE-2025-32327
was published
Sep 4, 2025
In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact...
High
Unreviewed
CVE-2025-32346
was published
Sep 4, 2025
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent...
High
Unreviewed
CVE-2025-32321
was published
Sep 4, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
High
CVE-2025-58179
was published
for
@astrojs/cloudflare
(npm)
Sep 4, 2025
It was possible to perform Remote Command Execution (RCE) via Java
RMI interface in the OpenEdge...
High
Unreviewed
CVE-2025-7388
was published
Sep 4, 2025
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin...
High
Unreviewed
CVE-2025-57263
was published
Sep 4, 2025
Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to...
High
Unreviewed
CVE-2024-34598
was published
Sep 4, 2025
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an...
High
Unreviewed
CVE-2025-41032
was published
Sep 4, 2025
A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability...
High
Unreviewed
CVE-2025-41035
was published
Sep 4, 2025
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an...
High
Unreviewed
CVE-2025-41033
was published
Sep 4, 2025
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an...
High
Unreviewed
CVE-2025-41034
was published
Sep 4, 2025
A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function...
High
Unreviewed
CVE-2025-9938
was published
Sep 4, 2025
In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic...
High
Unreviewed
CVE-2025-36905
was published
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API