GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
12,395 advisories
Filter by severity
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
Low
Unreviewed
CVE-2025-55188
was published
Aug 8, 2025
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low
CVE-2025-54999
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This...
Low
Unreviewed
CVE-2025-8708
was published
Aug 8, 2025
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25...
Low
Unreviewed
CVE-2024-56339
was published
Aug 7, 2025
Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors
Low
GHSA-vh9x-phq6-fx54
was published
for
github.com/rs/cors
(Go)
Aug 6, 2025
•
withdrawn
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive...
Low
Unreviewed
CVE-2025-38746
was published
Aug 6, 2025
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
GHSA-522r-9946-fw43
was published
for
github.com/cloudflare/circl
(Go)
Aug 6, 2025
•
withdrawn
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local...
Low
Unreviewed
CVE-2025-21022
was published
Aug 6, 2025
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local...
Low
Unreviewed
CVE-2025-21023
was published
Aug 6, 2025
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local...
Low
Unreviewed
CVE-2025-21024
was published
Aug 6, 2025
Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Low
CVE-2025-8573
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the...
Low
Unreviewed
CVE-2025-44964
was published
Aug 5, 2025
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects...
Low
Unreviewed
CVE-2025-8534
was published
Aug 5, 2025
Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if...
Low
Unreviewed
CVE-2025-7844
was published
Aug 5, 2025
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local...
Low
Unreviewed
CVE-2025-46094
was published
Aug 5, 2025
The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP...
Low
Unreviewed
CVE-2025-4599
was published
Aug 5, 2025
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4....
Low
Unreviewed
CVE-2025-8522
was published
Aug 4, 2025
A vulnerability was found in Intelbras InControl 2.21.60.9 and classified as problematic. This...
Low
Unreviewed
CVE-2025-8515
was published
Aug 4, 2025
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the...
Low
Unreviewed
CVE-2025-54956
was published
Aug 3, 2025
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit...
Low
Unreviewed
CVE-2025-54350
was published
Aug 3, 2025
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get...
Low
Unreviewed
CVE-2025-23290
was published
Aug 3, 2025
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access...
Low
Unreviewed
CVE-2025-23287
was published
Aug 3, 2025
ProTip!
Advisories are also available from the
GraphQL API