GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,263
NuGet
760
pip
4,058
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
301,580 advisories
Filter by severity
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-54709
was published
Sep 9, 2025
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-54894
was published
Sep 9, 2025
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation...
Critical
Unreviewed
CVE-2025-54261
was published
Sep 9, 2025
Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54112
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54114
was published
Sep 9, 2025
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54110
was published
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input...
Moderate
Unreviewed
CVE-2025-54247
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54115
was published
Sep 9, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection...
Moderate
Unreviewed
CVE-2025-54251
was published
Sep 9, 2025
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall...
Moderate
Unreviewed
CVE-2025-53810
was published
Sep 9, 2025
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-54095
was published
Sep 9, 2025
Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-54091
was published
Sep 9, 2025
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to...
High
Unreviewed
CVE-2025-54102
was published
Sep 9, 2025
Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker...
High
Unreviewed
CVE-2025-54093
was published
Sep 9, 2025
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall...
Moderate
Unreviewed
CVE-2025-54094
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-54092
was published
Sep 9, 2025
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-54098
was published
Sep 9, 2025
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-53806
was published
Sep 9, 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in...
High
Unreviewed
CVE-2025-53807
was published
Sep 9, 2025
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-54096
was published
Sep 9, 2025
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an...
Moderate
Unreviewed
CVE-2025-53809
was published
Sep 9, 2025
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized...
Moderate
Unreviewed
CVE-2025-54097
was published
Sep 9, 2025
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall...
Moderate
Unreviewed
CVE-2025-54104
was published
Sep 9, 2025
Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized...
High
Unreviewed
CVE-2025-54099
was published
Sep 9, 2025
Use after free in Windows Management Services allows an unauthorized attacker to elevate...
High
Unreviewed
CVE-2025-54103
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API