GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,713 advisories
Filter by severity
On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens...
Low
Unreviewed
CVE-2025-62774
was published
Oct 22, 2025
Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request...
Low
Unreviewed
CVE-2025-62773
was published
Oct 22, 2025
On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.
Low
Unreviewed
CVE-2025-62772
was published
Oct 22, 2025
Direct Ring Buffer has uninitialized memory exposure in create_ring_buffer
Low
GHSA-fp5x-7m4q-449f
was published
for
direct_ring_buffer
(Rust)
Oct 21, 2025
orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
Low
GHSA-h5j3-crg5-8jqm
was published
for
orx-pinned-vec
(Rust)
Oct 21, 2025
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component:...
Low
Unreviewed
CVE-2025-62480
was published
Oct 21, 2025
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block...
Low
Unreviewed
CVE-2025-62479
was published
Oct 21, 2025
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that...
Low
Unreviewed
CVE-2025-61749
was published
Oct 21, 2025
Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler). ...
Low
Unreviewed
CVE-2025-61755
was published
Oct 21, 2025
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2025-61748
was published
Oct 21, 2025
Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported...
Low
Unreviewed
CVE-2025-53051
was published
Oct 21, 2025
uv has differential in tar extraction with PAX headers
Low
GHSA-w476-p2h3-79g9
was published
for
uv
(pip)
Oct 21, 2025
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to path traversal via Plugin upload
Low
GHSA-6wh5-mw9h-5c3w
was published
for
shopware/core
(Composer)
Oct 21, 2025
Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that...
Low
Unreviewed
CVE-2025-11624
was published
Oct 21, 2025
A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown...
Low
Unreviewed
CVE-2025-9806
was published
Oct 21, 2025
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4...
Low
Unreviewed
CVE-2025-5496
was published
Oct 21, 2025
Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting...
Low
Unreviewed
CVE-2025-8049
was published
Oct 20, 2025
SQL Injection vulnerability in opentext Flipper allows SQL Injection.
The vulnerability could...
Low
Unreviewed
CVE-2025-8052
was published
Oct 20, 2025
Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting...
Low
Unreviewed
CVE-2025-8053
was published
Oct 20, 2025
rollbar vulnerable to prototype pollution
Low
CVE-2025-57325
was published
for
rollbar
(npm)
Oct 20, 2025
TastyIgniter vulnerable to Cross-Site Scripting
Low
CVE-2025-61417
was published
for
tastyigniter/tastyigniter
(Composer)
Oct 20, 2025
Tileservice module is affected by information leak vulnerability, successful exploitation of this...
Low
Unreviewed
CVE-2025-57837
was published
Oct 20, 2025
A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the...
Low
Unreviewed
CVE-2025-11947
was published
Oct 20, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-62653
was published
Oct 18, 2025
ProTip!
Advisories are also available from the
GraphQL API