GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,201 advisories
Filter by severity
mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders
Moderate
CVE-2025-59940
was published
for
mkdocs-include-markdown-plugin
(pip)
Sep 29, 2025
A vulnerability was detected in pmTicket Project-Management-Software up to...
Moderate
Unreviewed
CVE-2025-11135
was published
Sep 29, 2025
A vulnerability has been found in giantspatula SewKinect up to...
Moderate
Unreviewed
CVE-2025-10974
was published
Sep 26, 2025
A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997....
Moderate
Unreviewed
CVE-2025-10975
was published
Sep 26, 2025
A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue...
Moderate
Unreviewed
CVE-2025-10965
was published
Sep 25, 2025
Llama Stack could potentially allow for remote code execution
Moderate
CVE-2025-55178
was published
for
llama-stack
(pip)
Sep 24, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-10770
was published
Sep 22, 2025
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-10771
was published
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
Moderate
CVE-2025-59535
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-10769
was published
Sep 22, 2025
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function...
Moderate
Unreviewed
CVE-2025-10768
was published
Sep 22, 2025
Improper Input Validation vulnerability in Hallo Welt! GmbH BlueSpice (Extension...
Moderate
Unreviewed
CVE-2025-58114
was published
Sep 19, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker...
Moderate
Unreviewed
CVE-2025-23336
was published
Sep 18, 2025
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Moderate
CVE-2025-59160
was published
for
matrix-js-sdk
(npm)
Sep 16, 2025
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an...
Moderate
Unreviewed
CVE-2025-43375
was published
Sep 16, 2025
A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43299
was published
Sep 16, 2025
The issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7...
Moderate
Unreviewed
CVE-2025-43293
was published
Sep 16, 2025
A vulnerability was determined in 1Panel-dev MaxKB up to 2.0.2/2.1.0. This issue affects some...
Moderate
Unreviewed
CVE-2025-10433
was published
Sep 15, 2025
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw...
Moderate
Unreviewed
CVE-2024-45431
was published
Sep 12, 2025
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Moderate
CVE-2025-10164
was published
for
sglang
(pip)
Sep 9, 2025
TinyEnv: Inline comments not stripped properly in .env values
Moderate
CVE-2025-58759
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-54247
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API