GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
766
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,765 advisories
Filter by severity
Apache Struts Remote Java Code Execution
Critical
CVE-2012-0391
was published
for
org.apache.struts.xwork:xwork-core
(Maven)
May 4, 2022
A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4...
High
Unreviewed
CVE-2025-61136
was published
Oct 23, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-11905
was published
Oct 17, 2025
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-8483
was published
Oct 25, 2025
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso...
High
Unreviewed
CVE-2025-6204
was published
Aug 4, 2025
alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve...
High
Unreviewed
CVE-2025-56399
was published
Oct 28, 2025
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept...
Moderate
Unreviewed
CVE-2025-8848
was published
Oct 22, 2025
XWiki Platform allows remote code execution as guest via SolrSearchMacros request
Critical
CVE-2025-24893
was published
for
org.xwiki.platform:xwiki-platform-search-solr-ui
(Maven)
Feb 20, 2025
An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code...
High
Unreviewed
CVE-2025-61196
was published
Oct 30, 2025
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated...
High
Unreviewed
CVE-2025-48984
was published
Oct 31, 2025
The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code...
High
Unreviewed
CVE-2025-10487
was published
Nov 1, 2025
The kallyas theme for WordPress is vulnerable to Remote Code Execution in all versions up to, and...
High
Unreviewed
CVE-2025-6990
was published
Nov 1, 2025
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise...
Critical
Unreviewed
CVE-2014-5401
was published
May 13, 2022
An issue was discovered in badaix Snapcast version 0.27.0, allows remote attackers to execute...
Critical
Unreviewed
CVE-2023-36177
was published
Jan 24, 2024
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file...
Moderate
Unreviewed
CVE-2023-6601
was published
Jan 6, 2025
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage...
Moderate
Unreviewed
CVE-2023-6604
was published
Jan 6, 2025
A validation issue was addressed with improved logic. This issue is fixed in iPadOS 17.7.4, macOS...
High
Unreviewed
CVE-2025-24159
was published
Jan 28, 2025
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an...
Critical
Unreviewed
CVE-2025-1011
was published
Feb 4, 2025
In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at...
Critical
Unreviewed
CVE-2024-53920
was published
Nov 27, 2024
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27657
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27678
was published
Mar 5, 2025
graphql allows remote code execution when loading a crafted GraphQL schema
Critical
CVE-2025-27407
was published
for
graphql
(RubyGems)
Mar 12, 2025
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited...
High
Unreviewed
CVE-2024-58258
was published
Jul 14, 2025
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user...
High
Unreviewed
CVE-2025-8030
was published
Jul 22, 2025
ProTip!
Advisories are also available from the
GraphQL API