GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
60 advisories
Filter by severity
An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file...
High
Unreviewed
CVE-2025-48416
was published
May 21, 2025
Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request...
Low
Unreviewed
CVE-2025-62773
was published
Oct 22, 2025
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM...
Low
Unreviewed
CVE-2025-47729
was published
May 8, 2025
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker...
Critical
Unreviewed
CVE-2024-20439
was published
Sep 4, 2024
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF...
High
Unreviewed
CVE-2021-25371
was published
May 24, 2022
Multiple versions of RG-EST300 provided by Ruijie Networks provide SSH server functionality. It...
High
Unreviewed
CVE-2025-58778
was published
Oct 16, 2025
SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged...
High
Unreviewed
CVE-2025-11673
was published
Oct 13, 2025
sweetalert2 v8.19.1 and above contains hidden functionality
Low
GHSA-8jh9-wqpf-q52c
was published
for
sweetalert2
(npm)
Nov 23, 2022
sweetalert2 v9.17.4 and above contains hidden functionality
Low
GHSA-pg98-6v7f-2xfv
was published
for
sweetalert2
(npm)
Nov 23, 2022
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed...
Critical
Unreviewed
CVE-2010-20103
was published
Aug 20, 2025
Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is...
Moderate
Unreviewed
CVE-2025-55075
was published
Sep 17, 2025
sweetalert2 v11.4.9 and above contains hidden functionality
Low
GHSA-qq6h-5g6j-q3cm
was published
for
sweetalert2
(npm)
Nov 23, 2022
sweetalert2 v10.16.10 and above contains hidden functionality
Low
GHSA-457r-cqc8-9vj9
was published
for
sweetalert2
(npm)
Nov 23, 2022
A weakness has been identified in FNKvision Y215 CCTV Camera 10.194.120.40. This vulnerability...
Moderate
Unreviewed
CVE-2025-9382
was published
Aug 24, 2025
A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function...
Moderate
Unreviewed
CVE-2025-8938
was published
Aug 14, 2025
Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's...
Moderate
Unreviewed
CVE-2025-46267
was published
Jul 22, 2025
A vulnerability, which was classified as critical, has been found in Conjure Position Department...
Moderate
Unreviewed
CVE-2025-6839
was published
Jun 29, 2025
The SIMCom SIM7600G modem supports an undocumented AT command, which allows an attacker to...
Moderate
Unreviewed
CVE-2025-26412
was published
Jun 11, 2025
Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code...
Critical
Unreviewed
CVE-2022-46997
was published
Dec 14, 2022
vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code...
Critical
Unreviewed
CVE-2022-46996
was published
Dec 14, 2022
The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application...
High
Unreviewed
CVE-2022-1741
was published
Jun 25, 2022
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions...
High
Unreviewed
CVE-2025-32370
was published
Apr 6, 2025
Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1...
Moderate
Unreviewed
CVE-2023-22316
was published
Jan 17, 2023
The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of...
Moderate
Unreviewed
CVE-2025-2894
was published
Mar 28, 2025
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super...
Critical
Unreviewed
CVE-2022-47767
was published
Jan 26, 2023
ProTip!
Advisories are also available from the
GraphQL API