GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,123
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
67 advisories
Filter by severity
Singluarity ineffectively applies selinux / apparmor LSM process labels
Moderate
CVE-2025-64750
was published
for
github.com/sylabs/singularity/v4
(Go)
Dec 2, 2025
Apptainer ineffectively applies selinux and apparmor --security options
Moderate
CVE-2025-65105
was published
for
github.com/apptainer/apptainer
(Go)
Dec 2, 2025
zx Uses Incorrectly-Resolved Name or Reference
Moderate
CVE-2025-13437
was published
for
zx
(npm)
Nov 20, 2025
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API...
Critical
Unreviewed
CVE-2021-40539
was published
May 24, 2022
MobileIron Core and Connector before 10.3.0.4, 10.4.x before 10.4.0.4, 10.5.x before 10.5.1.1, 10...
High
Unreviewed
CVE-2020-15505
was published
May 24, 2022
CommandKit has incorrect command name exposure in context object for message command aliases
Moderate
CVE-2025-62378
was published
for
commandkit
(npm)
Oct 13, 2025
Hono's flaw in URL path parsing could cause path confusion
High
CVE-2025-58362
was published
for
hono
(npm)
Sep 3, 2025
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2023-42125
was published
May 3, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2025-24733
was published
Jan 24, 2025
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara...
Moderate
Unreviewed
CVE-2025-3941
was published
May 22, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-48136
was published
May 16, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30870
was published
Apr 1, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30849
was published
Apr 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read...
Moderate
Unreviewed
CVE-2021-47276
was published
May 21, 2024
In the Linux kernel, the following vulnerability has been resolved:
IB/mlx5: Fix initializing CQ...
High
Unreviewed
CVE-2021-47261
was published
May 21, 2024
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version...
Critical
Unreviewed
CVE-2021-37315
was published
Feb 3, 2023
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Moderate
CVE-2025-29914
was published
for
github.com/corazawaf/coraza/v3
(Go)
Mar 20, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53739
was published
Nov 30, 2024
Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via...
Moderate
Unreviewed
CVE-2024-57785
was published
Jan 17, 2025
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model...
Critical
Unreviewed
CVE-2023-31814
was published
May 23, 2023
An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online...
Moderate
Unreviewed
CVE-2024-55058
was published
Dec 17, 2024
Opencontainers runc Incorrect Authorization vulnerability
High
CVE-2023-27561
was published
for
github.com/opencontainers/runc
(Go)
Mar 3, 2023
Nuxt vulnerable to remote code execution via the browser when running the test locally
Critical
CVE-2024-34344
was published
for
nuxt
(npm)
Aug 5, 2024
gitsign may use incorrect Rekor entries during verification
Low
CVE-2024-51746
was published
for
github.com/sigstore/gitsign
(Go)
Nov 5, 2024
The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all...
High
Unreviewed
CVE-2024-4887
was published
Jun 7, 2024
ProTip!
Advisories are also available from the
GraphQL API