GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,971 advisories
Filter by severity
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2022-20630
was published
Feb 11, 2022
A vulnerability in the management API of Cisco DNA Center could allow an authenticated, remote...
High
Unreviewed
CVE-2023-20055
was published
Mar 23, 2023
A vulnerability in Cisco DNA Center software could allow an unauthenticated remote attacker...
Moderate
Unreviewed
CVE-2020-3411
was published
May 24, 2022
Grafana's insecure DingDing Alert integration exposes sensitive information
Moderate
CVE-2025-3415
was published
for
github.com/grafana/grafana
(Go)
Jul 17, 2025
Indico vulnerability allows attackers to bulk dump user details
Moderate
CVE-2025-53640
was published
for
indico
(pip)
Jul 14, 2025
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the...
Moderate
Unreviewed
CVE-2025-52372
was published
Jul 21, 2025
Mattermost password hash disclosure vulnerability
Moderate
CVE-2023-5968
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 6, 2023
The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all...
Moderate
Unreviewed
CVE-2025-6082
was published
Jul 22, 2025
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability,...
High
Unreviewed
CVE-2025-7919
was published
Jul 21, 2025
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Moderate
Unreviewed
CVE-2025-46382
was published
Jul 20, 2025
A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.2. It has been rated as problematic....
Moderate
Unreviewed
CVE-2025-7874
was published
Jul 20, 2025
In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as...
High
Unreviewed
CVE-2025-7394
was published
Jul 19, 2025
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user...
Low
Unreviewed
CVE-2024-42209
was published
Jul 17, 2025
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22....
Moderate
Unreviewed
CVE-2025-7565
was published
Jul 14, 2025
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior...
High
Unreviewed
CVE-2025-34130
was published
Jul 17, 2025
Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
Moderate
CVE-2025-22227
was published
for
io.projectreactor.netty:reactor-netty-http
(Maven)
Jul 16, 2025
Liferay Portal and Liferay DXP Includes LDAP Credentials in the Page URL
Moderate
CVE-2022-42132
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Nov 15, 2022
Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)...
Moderate
Unreviewed
CVE-2025-30758
was published
Jul 15, 2025
Directus' exact version number is exposed by the OpenAPI Spec
Moderate
CVE-2025-53887
was published
for
directus
(npm)
Jul 15, 2025
Directus tokens are not redacted in flow logs, exposing session credentials to all admin
Moderate
CVE-2025-53886
was published
for
directus
(npm)
Jul 15, 2025
When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when...
High
Unreviewed
CVE-2025-6432
was published
Jun 26, 2025
In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability...
High
Unreviewed
CVE-2024-11031
was published
Mar 20, 2025
An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
High
Unreviewed
CVE-2024-51769
was published
Jul 14, 2025
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC1900, BL...
Moderate
Unreviewed
CVE-2025-7573
was published
Jul 14, 2025
A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600,...
Moderate
Unreviewed
CVE-2025-7572
was published
Jul 14, 2025
ProTip!
Advisories are also available from the
GraphQL API