GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
145,527 advisories
Filter by severity
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-7929
was published
Jul 21, 2025
Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows...
Moderate
Unreviewed
CVE-2025-52374
was published
Jul 21, 2025
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the...
Moderate
Unreviewed
CVE-2025-52372
was published
Jul 21, 2025
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows...
Moderate
Unreviewed
CVE-2025-52373
was published
Jul 21, 2025
Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before...
Moderate
Unreviewed
CVE-2024-55040
was published
Jul 21, 2025
A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet...
Moderate
Unreviewed
CVE-2025-7926
was published
Jul 21, 2025
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application ...
Moderate
Unreviewed
CVE-2025-43977
was published
Jul 21, 2025
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed...
Moderate
Unreviewed
CVE-2025-43976
was published
Jul 21, 2025
A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-7928
was published
Jul 21, 2025
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a...
Moderate
Unreviewed
CVE-2025-6235
was published
Jul 21, 2025
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.12.304, where an...
Moderate
Unreviewed
CVE-2025-46119
was published
Jul 21, 2025
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139...
Moderate
Unreviewed
CVE-2025-46122
was published
Jul 21, 2025
An issue was discovered in CommScope Ruckus Unleashed prior to 200.14.6.1.203 and in Ruckus...
Moderate
Unreviewed
CVE-2025-46120
was published
Jul 21, 2025
A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-7927
was published
Jul 21, 2025
A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Banquet...
Moderate
Unreviewed
CVE-2025-7925
was published
Jul 21, 2025
Incorrect authentication vulnerability in ParkingDoor. Through this vulnerability it is possible...
Moderate
Unreviewed
CVE-2025-41100
was published
Jul 21, 2025
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0...
Moderate
Unreviewed
CVE-2024-13973
was published
Jul 21, 2025
A vulnerability classified as problematic was found in PHPGurukul Online Banquet Booking System 1...
Moderate
Unreviewed
CVE-2025-7924
was published
Jul 21, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows...
Moderate
Unreviewed
CVE-2025-5681
was published
Jul 21, 2025
Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local...
Moderate
Unreviewed
CVE-2025-41458
was published
Jul 21, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Akbim Software Online Exam...
Moderate
Unreviewed
CVE-2025-2301
was published
Jul 21, 2025
Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
Moderate
CVE-2025-49656
was published
for
org.apache.jena:jena-fuseki
(Maven)
Jul 21, 2025
A high privileged remote attacker can exhaust critical system resources by sending specifically...
Moderate
Unreviewed
CVE-2025-41677
was published
Jul 21, 2025
A high privileged remote attacker can exhaust critical system resources by sending specifically...
Moderate
Unreviewed
CVE-2025-41676
was published
Jul 21, 2025
A high privileged remote attacker can gain persistent XSS via POST requests due to improper...
Moderate
Unreviewed
CVE-2025-41681
was published
Jul 21, 2025
ProTip!
Advisories are also available from the
GraphQL API