GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
143 advisories
Filter by severity
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-49649
was published
Jan 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-56216
was published
Dec 31, 2024
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
High
CVE-2024-28184
was published
for
weasyprint
(pip)
Mar 8, 2024
Apache HDFS Provider error message suggested
High
CVE-2023-41267
was published
for
apache-airflow-providers-apache-hdfs
(pip)
Sep 14, 2023
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin...
High
Unreviewed
CVE-2024-13353
was published
Feb 21, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27668
was published
Mar 5, 2025
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B...
High
Unreviewed
CVE-2024-45482
was published
Mar 25, 2025
An iframe that was not permitted to run scripts could do so if the user clicked on a <code...
High
Unreviewed
CVE-2022-34468
was published
Dec 22, 2022
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated,...
High
Unreviewed
CVE-2025-20236
was published
Apr 16, 2025
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-33026
was published
Apr 15, 2025
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This...
Moderate
Unreviewed
CVE-2025-33027
was published
Apr 15, 2025
Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd...
Moderate
Unreviewed
CVE-2024-52976
was published
May 1, 2025
Markdownify subject to Remote Code Execution via malicious markdown file
High
CVE-2022-41709
was published
for
electron-markdownify
(npm)
Oct 19, 2022
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-39507
was published
May 16, 2025
A flaw was found in Yelp. The Gnome user help application allows the help document to execute...
Moderate
Unreviewed
CVE-2025-3155
was published
Apr 3, 2025
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by...
High
Unreviewed
CVE-2025-49809
was published
Jul 4, 2025
The Secure Password extension in One Identity Password Manager before 5.14.4 allows local...
High
Unreviewed
CVE-2025-27582
was published
Jul 14, 2025
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or -...
Moderate
Unreviewed
CVE-2025-54558
was published
Jul 25, 2025
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue...
High
Unreviewed
CVE-2025-36727
was published
Jul 25, 2025
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an...
Critical
Unreviewed
CVE-2025-0982
was published
Feb 6, 2025
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin...
High
Unreviewed
CVE-2025-8714
was published
Aug 14, 2025
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic...
Moderate
Unreviewed
CVE-2025-57729
was published
Aug 20, 2025
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49134
was published
Apr 9, 2024
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49133
was published
Apr 9, 2024
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
ProTip!
Advisories are also available from the
GraphQL API