GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
463 advisories
Filter by severity
An Improper Handling of Exceptional Conditions vulnerability in route processing of Juniper...
High
Unreviewed
CVE-2025-52947
was published
Jul 11, 2025
An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF)...
High
Unreviewed
CVE-2025-52948
was published
Jul 11, 2025
Certain instructions need intercepting and emulating by Xen. In some
cases Xen emulates the...
Moderate
Unreviewed
CVE-2025-27465
was published
Jul 16, 2025
Vulnerability of improper processing of abnormal conditions in huge page separation.
Impact:...
High
Unreviewed
CVE-2025-54634
was published
Aug 6, 2025
Volto affected by possible DoS by invoking specific URL by anonymous user
High
CVE-2025-58047
was published
for
@plone/volto
(npm)
Aug 28, 2025
A security issue exists in the protected mode of EN4TR devices, where sending specifically...
High
Unreviewed
CVE-2025-8008
was published
Sep 9, 2025
Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
CVE-2025-10156
was published
for
picklescan
(pip)
Sep 10, 2025
Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
GHSA-4vr7-g93g-cf6m
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application include Windows...
High
Unreviewed
CVE-2025-34193
was published
Sep 19, 2025
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
High
CVE-2025-59530
was published
for
github.com/quic-go/quic-go
(Go)
Oct 10, 2025
A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the...
High
Unreviewed
CVE-2025-9437
was published
Oct 14, 2025
Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated...
High
Unreviewed
CVE-2025-53702
was published
Oct 23, 2025
Wasmtime vulnerable to segfault when using component resources
Low
CVE-2025-62711
was published
for
wasmtime
(Rust)
Oct 27, 2025
ProTip!
Advisories are also available from the
GraphQL API