GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,577 advisories
Filter by severity
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
High
Unreviewed
CVE-2025-54248
was published
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-54250
was published
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-54247
was published
Sep 9, 2025
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an...
Moderate
Unreviewed
CVE-2025-53809
was published
Sep 9, 2025
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could...
High
Unreviewed
CVE-2023-32701
was published
Nov 14, 2023
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0,...
Critical
Unreviewed
CVE-2024-35213
was published
Jun 11, 2024
Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an...
High
Unreviewed
CVE-2021-37150
was published
Aug 11, 2022
In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to...
High
Unreviewed
CVE-2022-20356
was published
Aug 11, 2022
Improper Input Validation vulnerability in ABB 800xA Base.
An attacker who successfully exploited...
Moderate
Unreviewed
CVE-2024-3036
was published
Jun 21, 2024
A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer...
High
Unreviewed
CVE-2025-4600
was published
May 16, 2025
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import")...
Low
Unreviewed
CVE-2024-5899
was published
Jun 18, 2024
An authorized user can cause a crash in the MongoDB Server through a specially crafted $group...
Moderate
Unreviewed
CVE-2025-10061
was published
Sep 5, 2025
In getCallingAppName of Shared.java, there is a possible way to trick users into granting file...
High
Unreviewed
CVE-2025-32323
was published
Sep 4, 2025
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1...
Moderate
Unreviewed
CVE-2023-21472
was published
Sep 5, 2025
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1...
Moderate
Unreviewed
CVE-2023-21473
was published
Sep 5, 2025
Velocidex WinPmem versions below 4.1 suffer from an Improper Input Validation vulnerability...
High
Unreviewed
CVE-2024-10972
was published
Dec 16, 2024
In multiple methods of NotificationChannel.java, there is a possible desynchronization from...
High
Unreviewed
CVE-2025-48556
was published
Sep 4, 2025
In onCreate of FaceSettings.java, there is a possible way to remove biometric unlock across user...
High
Unreviewed
CVE-2025-48541
was published
Sep 4, 2025
In multiple locations, there is a possible way to persistently DoS the device due to improper...
High
Unreviewed
CVE-2025-48537
was published
Sep 4, 2025
In onCreate of MediaProjectionPermissionActivity.java , there is a possible way to grant a...
High
Unreviewed
CVE-2025-32322
was published
Sep 4, 2025
In multiple functions of AppOpsService.java, there is a possible add a large amount of app ops...
Moderate
Unreviewed
CVE-2025-48559
was published
Sep 4, 2025
In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to...
Moderate
Unreviewed
CVE-2025-26426
was published
Sep 4, 2025
In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to...
Moderate
Unreviewed
CVE-2025-26429
was published
Sep 4, 2025
In setApplicationHiddenSettingAsUser of PackageManagerService.java, there is a possible way to...
Moderate
Unreviewed
CVE-2025-48538
was published
Sep 4, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
ProTip!
Advisories are also available from the
GraphQL API