GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
276,824 advisories
Filter by severity
A flaw was found in the integration of Active Directory and the System Security Services Daemon ...
High
Unreviewed
CVE-2025-11561
was published
Oct 9, 2025
The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter...
Unknown
Unreviewed
CVE-2025-11560
was published
Nov 12, 2025
The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-12901
was published
Nov 12, 2025
The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure...
Moderate
Unreviewed
CVE-2025-12087
was published
Nov 12, 2025
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for...
Moderate
Unreviewed
CVE-2025-12833
was published
Nov 12, 2025
A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4...
Moderate
Unreviewed
CVE-2025-54983
was published
Nov 12, 2025
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix Use-after...
Unknown
Unreviewed
CVE-2025-40111
was published
Nov 12, 2025
In the Linux kernel, the following vulnerability has been resolved:
drm/vmwgfx: Fix a null-ptr...
Unknown
Unreviewed
CVE-2025-40110
was published
Nov 12, 2025
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when...
High
Unreviewed
CVE-2025-9900
was published
Sep 23, 2025
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in...
Unknown
Unreviewed
CVE-2025-43205
was published
Nov 12, 2025
Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a...
Moderate
Unreviewed
CVE-2025-12447
was published
Nov 10, 2025
A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management...
Moderate
Unreviewed
CVE-2025-3146
was published
Apr 3, 2025
A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client...
High
Unreviewed
CVE-2025-62230
was published
Oct 30, 2025
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username...
Moderate
Unreviewed
CVE-2025-56764
was published
Sep 29, 2025
A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by...
High
Unreviewed
CVE-2025-11021
was published
Sep 26, 2025
A vulnerability has been identified in POWER METER SICAM Q200 family (All versions < V2.70)....
Moderate
Unreviewed
CVE-2023-31238
was published
Jun 13, 2023
A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME...
Low
Unreviewed
CVE-2025-4945
was published
May 19, 2025
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The...
High
Unreviewed
CVE-2024-32010
was published
Nov 11, 2025
Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability...
Moderate
Unreviewed
CVE-2025-61840
was published
Nov 11, 2025
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of...
Moderate
Unreviewed
CVE-2025-12748
was published
Nov 11, 2025
Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability...
Moderate
Unreviewed
CVE-2025-61844
was published
Nov 11, 2025
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The...
High
Unreviewed
CVE-2024-32009
was published
Nov 11, 2025
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected...
High
Unreviewed
CVE-2025-40763
was published
Nov 11, 2025
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO!...
High
Unreviewed
CVE-2025-40816
was published
Nov 11, 2025
When using the Grafana Snowflake Datasource Plugin,
if Oauth passthrough is enabled on the...
Low
Unreviewed
CVE-2025-3717
was published
Nov 11, 2025
ProTip!
Advisories are also available from the
GraphQL API