GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,575 advisories
Filter by severity
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged...
High
Unreviewed
CVE-2023-34440
was published
Feb 13, 2025
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged...
Moderate
Unreviewed
CVE-2024-28047
was published
Feb 13, 2025
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged...
High
Unreviewed
CVE-2024-28127
was published
Feb 13, 2025
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may...
High
Unreviewed
CVE-2024-24582
was published
Feb 13, 2025
Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged...
High
Unreviewed
CVE-2023-43758
was published
Feb 13, 2025
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a ...
High
Unreviewed
CVE-2024-45236
was published
Aug 25, 2024
A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed...
Moderate
Unreviewed
CVE-2022-41861
was published
Jan 17, 2023
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache...
High
Unreviewed
CVE-2024-38479
was published
Nov 14, 2024
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation...
High
Unreviewed
CVE-2021-36047
was published
May 24, 2022
XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation...
High
Unreviewed
CVE-2021-36048
was published
May 24, 2022
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain...
Moderate
Unreviewed
CVE-2024-8445
was published
Sep 5, 2024
It was discovered that apport in data/apport did not properly open a report file to prevent...
High
Unreviewed
CVE-2021-25684
was published
May 24, 2022
A remote code execution vulnerability in UCB component of Mitel MiVoice Connect before 19.1 SP1...
High
Unreviewed
CVE-2020-10211
was published
May 24, 2022
The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the...
Critical
Unreviewed
CVE-2025-64385
was published
Oct 31, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote...
Low
Unreviewed
CVE-2014-5398
was published
May 17, 2022
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
Moderate
CVE-2025-11226
was published
for
ch.qos.logback:logback-core
(Maven)
Oct 1, 2025
HCL DRYiCE
AEX product is impacted by lack of input validation vulnerability in a particular web...
Critical
Unreviewed
CVE-2024-30110
was published
Oct 30, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability....
Moderate
Unreviewed
CVE-2025-52620
was published
Aug 16, 2025
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Moderate
CVE-2025-10164
was published
for
sglang
(pip)
Sep 9, 2025
An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public...
Critical
Unreviewed
CVE-2025-61235
was published
Oct 28, 2025
TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload...
Critical
Unreviewed
CVE-2025-27224
was published
Oct 27, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to...
Critical
Unreviewed
CVE-2025-34132
was published
Jul 17, 2025
ProTip!
Advisories are also available from the
GraphQL API