GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,768 advisories
Filter by severity
The vulnerability was identified in the code developed specifically for Lenovo. Please visit ...
Moderate
Unreviewed
CVE-2025-4426
was published
Jul 30, 2025
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS...
Moderate
Unreviewed
CVE-2025-43246
was published
Jul 30, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6....
Moderate
Unreviewed
CVE-2025-43215
was published
Jul 30, 2025
Umbraco Delivery API allows for cached requests to be returned with an invalid API key
Moderate
CVE-2025-54425
was published
for
Umbraco.Cms.Api.Delivery
(NuGet)
Jul 29, 2025
Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLs
Moderate
CVE-2025-50738
was published
for
github.com/usememos/memos
(Go)
Jul 29, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as...
Moderate
Unreviewed
CVE-2025-8226
was published
Jul 27, 2025
Opencast still publishes global system account credentials
Moderate
CVE-2025-54380
was published
for
org.opencastproject:opencast-common
(Maven)
Jul 25, 2025
Certain HP DesignJet products may be vulnerable to information disclosure though printer's web...
Moderate
Unreviewed
CVE-2025-3508
was published
Jul 25, 2025
The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-7780
was published
Jul 25, 2025
Possible ORM Leak Vulnerability in the Harbor
Moderate
CVE-2025-30086
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all...
Moderate
Unreviewed
CVE-2025-6082
was published
Jul 22, 2025
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the...
Moderate
Unreviewed
CVE-2025-52372
was published
Jul 21, 2025
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Moderate
Unreviewed
CVE-2025-46382
was published
Jul 20, 2025
A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic....
Moderate
Unreviewed
CVE-2025-7874
was published
Jul 20, 2025
Grafana's insecure DingDing Alert integration exposes sensitive information
Moderate
CVE-2025-3415
was published
for
github.com/grafana/grafana
(Go)
Jul 17, 2025
Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
Moderate
CVE-2025-22227
was published
for
io.projectreactor.netty:reactor-netty-http
(Maven)
Jul 16, 2025
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)...
Moderate
Unreviewed
CVE-2025-30758
was published
Jul 15, 2025
Directus' exact version number is exposed by the OpenAPI Spec
Moderate
CVE-2025-53887
was published
for
directus
(npm)
Jul 15, 2025
Directus tokens are not redacted in flow logs, exposing session credentials to all admin
Moderate
CVE-2025-53886
was published
for
directus
(npm)
Jul 15, 2025
Indico vulnerability allows attackers to bulk dump user details
Moderate
CVE-2025-53640
was published
for
indico
(pip)
Jul 14, 2025
A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600,...
Moderate
Unreviewed
CVE-2025-7572
was published
Jul 14, 2025
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL...
Moderate
Unreviewed
CVE-2025-7573
was published
Jul 14, 2025
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22....
Moderate
Unreviewed
CVE-2025-7565
was published
Jul 14, 2025
The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2025-4593
was published
Jul 11, 2025
The WoodMart plugin for WordPress is vulnerable to Information Exposure in all versions up to,...
Moderate
Unreviewed
CVE-2025-6745
was published
Jul 11, 2025
ProTip!
Advisories are also available from the
GraphQL API