GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,262
NuGet
760
pip
4,058
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,971 advisories
Filter by severity
Information Disclosure in Amazon ECS Container Agent
Moderate
CVE-2025-9039
was published
for
github.com/aws/amazon-ecs-agent
(Go)
Aug 14, 2025
A security issue in the runtime event system allows unauthenticated connections to receive a...
High
Unreviewed
CVE-2025-9036
was published
Aug 14, 2025
KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi),...
High
Unreviewed
CVE-2025-43988
was published
Aug 13, 2025
An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service...
Critical
Unreviewed
CVE-2025-43986
was published
Aug 13, 2025
A flaw was found in the Openshift console. Several endpoints in the application use the...
Moderate
Unreviewed
CVE-2024-7128
was published
Jul 26, 2024
Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an...
High
Unreviewed
CVE-2025-53781
was published
Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an...
Moderate
Unreviewed
CVE-2025-53156
was published
Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an...
High
Unreviewed
CVE-2025-33051
was published
Aug 12, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-53134
was published
Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises...
Moderate
Unreviewed
CVE-2025-53728
was published
Aug 12, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Low
Unreviewed
CVE-2025-27707
was published
Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an...
Moderate
Unreviewed
CVE-2025-53136
was published
Aug 12, 2025
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to...
High
Unreviewed
CVE-2025-3831
was published
Aug 12, 2025
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions ...
High
Unreviewed
CVE-2025-40768
was published
Aug 12, 2025
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure...
Moderate
Unreviewed
CVE-2025-4390
was published
Aug 12, 2025
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster...
Moderate
Unreviewed
CVE-2025-8866
was published
Aug 11, 2025
MantisBT may disclose project names to unauthorized users
Moderate
CVE-2023-44394
was published
for
mantisbt/mantisbt
(Composer)
Oct 17, 2023
The AuthKit React Router Library rendered sensitive auth data in HTML
High
CVE-2025-55008
was published
for
@workos-inc/authkit-react-router
(npm)
Aug 8, 2025
A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as...
Moderate
Unreviewed
CVE-2025-8738
was published
Aug 8, 2025
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2024-58257
was published
Aug 8, 2025
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2024-58256
was published
Aug 8, 2025
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability...
Moderate
Unreviewed
CVE-2024-58255
was published
Aug 8, 2025
Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the...
High
Unreviewed
CVE-2025-51040
was published
Aug 6, 2025
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can...
High
Unreviewed
CVE-2025-46659
was published
Aug 6, 2025
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive...
Low
Unreviewed
CVE-2025-38746
was published
Aug 6, 2025
ProTip!
Advisories are also available from the
GraphQL API