GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,563 advisories
Filter by severity
Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140...
Unknown
Unreviewed
CVE-2025-12908
was published
Nov 8, 2025
Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80...
Unknown
Unreviewed
CVE-2025-12907
was published
Nov 8, 2025
Magento affected by a server-side denial-of-service using a GraphQL field
High
CVE-2021-36044
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento executes code via the API File Option Upload Extension
Critical
CVE-2021-36042
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento vulnerable to file upload attack
High
CVE-2021-36041
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento has a file extension restrictions bypass
Critical
CVE-2021-36040
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento discloses sensitive information via the Multishipping Module
Moderate
CVE-2021-36038
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento affected by remote code execution via a file upload
High
CVE-2021-36034
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento is affected by an improper input validation vulnerability while saving a customer's details
Critical
CVE-2021-36025
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento is affected by an improper input validation vulnerability
High
CVE-2021-36032
was published
for
magento/community-edition
(Composer)
May 24, 2022
Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU...
Critical
Unreviewed
CVE-2025-12001
was published
Oct 21, 2025
Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19...
Critical
Unreviewed
CVE-2025-12275
was published
Oct 26, 2025
Magento allows attackers to alter the price of items
High
CVE-2021-36030
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento affected by remote code execution vulnerability in the CMS page scheduled update feature
Critical
CVE-2021-36021
was published
for
magento/community-edition
(Composer)
Sep 6, 2023
A denial-of-service issue was addressed with improved input validation. This issue is fixed in...
Low
Unreviewed
CVE-2025-43365
was published
Nov 4, 2025
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function...
Moderate
Unreviewed
CVE-2025-12305
was published
Oct 27, 2025
This issue was addressed through improved state management. This issue is fixed in Safari 26.1,...
Moderate
Unreviewed
CVE-2025-43458
was published
Nov 4, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
Apache DolphinScheduler vulnerable to Alert Script Attack
High
CVE-2024-43115
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 9, 2025
Apache CXF: Untrusted JMS configuration can lead to RCE
Moderate
CVE-2025-48913
was published
for
org.apache.cxf:cxf-rt-transports-jms
(Maven)
Aug 8, 2025
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
Moderate
CVE-2024-52279
was published
for
org.apache.zeppelin:zeppelin-jdbc
(Maven)
Aug 3, 2025
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
High
CVE-2025-50151
was published
for
org.apache.jena:jena
(Maven)
Jul 21, 2025
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle...
High
Unreviewed
CVE-2025-61084
was published
Nov 5, 2025
JDBC Driver for SQL Server has improper input validation issue
High
CVE-2025-59250
was published
for
com.microsoft.sqlserver:mssql-jdbc
(Maven)
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API