GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,643
Maven
5,000+
npm
4,268
NuGet
760
pip
4,062
Pub
12
RubyGems
956
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,975 advisories
Filter by severity
Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto...
Moderate
Unreviewed
CVE-2022-25664
was published
Oct 19, 2022
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics ...
Moderate
Unreviewed
CVE-2024-20904
was published
Jan 17, 2024
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
High
CVE-2024-34005
was published
for
moodle/moodle
(Composer)
May 31, 2024
An issue in realme GT 2 (RMX3311) running Android 14 with realme UI 5.0 allows a physically...
Moderate
Unreviewed
CVE-2025-25370
was published
May 14, 2025
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf...
High
Unreviewed
CVE-2025-3877
was published
May 14, 2025
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via...
Moderate
Unreviewed
CVE-2024-57096
was published
May 14, 2025
This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13....
Moderate
Unreviewed
CVE-2022-32931
was published
Jan 11, 2024
An access issue was addressed with improved access restrictions. This issue is fixed in watchOS...
Moderate
Unreviewed
CVE-2024-23206
was published
Jan 23, 2024
In telephony service, there is a missing permission check. This could lead to local information...
Moderate
Unreviewed
CVE-2022-38688
was published
Oct 15, 2022
In telephony service, there is a missing permission check. This could lead to local information...
Moderate
Unreviewed
CVE-2022-38689
was published
Oct 15, 2022
MantisBT vulnerable to information disclosure with user profiles
Moderate
CVE-2024-45792
was published
for
mantisbt/mantisbt
(Composer)
Sep 30, 2024
OXID eShop May Display User Information
High
CVE-2024-56526
was published
for
oxid-esales/oxideshop-ce
(Composer)
May 13, 2025
Liferay Portal and Liferay DXP Fails to Sanitize API Data
Moderate
CVE-2020-13444
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which...
Moderate
Unreviewed
CVE-2024-0340
was published
Jan 9, 2024
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Moderate
Unreviewed
CVE-2025-22895
was published
May 13, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Moderate
Unreviewed
CVE-2025-20624
was published
May 13, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Moderate
Unreviewed
CVE-2025-20611
was published
May 13, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Moderate
Unreviewed
CVE-2025-20013
was published
May 13, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Low
Unreviewed
CVE-2025-20030
was published
May 13, 2025
The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-4222
was published
May 3, 2025
Insufficient granularity of access control in Visual Studio allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-32703
was published
May 13, 2025
A vulnerability has been found in Gosuncn Technology Group Audio-Visual Integrated Management...
Moderate
Unreviewed
CVE-2025-4536
was published
May 11, 2025
A vulnerability, which was classified as problematic, was found in Gosuncn Technology Group Audio...
Moderate
Unreviewed
CVE-2025-4535
was published
May 11, 2025
A vulnerability, which was classified as problematic, was found in Dígitro NGC Explorer 3.44.15....
Moderate
Unreviewed
CVE-2025-4526
was published
May 11, 2025
Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens
Moderate
CVE-2022-31684
was published
for
io.projectreactor.netty:reactor-netty-http
(Maven)
Oct 20, 2022
ProTip!
Advisories are also available from the
GraphQL API