GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
105,296 advisories
Filter by severity
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed...
High
Unreviewed
CVE-2025-12726
was published
Nov 10, 2025
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote...
High
Unreviewed
CVE-2025-12429
was published
Nov 10, 2025
Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially...
High
Unreviewed
CVE-2025-12432
was published
Nov 10, 2025
Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a...
High
Unreviewed
CVE-2025-12438
was published
Nov 10, 2025
Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with...
High
Unreviewed
CVE-2025-46430
was published
Nov 10, 2025
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed...
High
Unreviewed
CVE-2025-63455
was published
Nov 10, 2025
A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database...
High
Unreviewed
CVE-2025-63711
was published
Nov 10, 2025
In JetBrains YouTrack before 2025.3.104432 missing VCS URL validation allowed delegation to...
High
Unreviewed
CVE-2025-64688
was published
Nov 10, 2025
In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data...
High
Unreviewed
CVE-2025-64685
was published
Nov 10, 2025
In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows...
High
Unreviewed
CVE-2025-64456
was published
Nov 10, 2025
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC...
High
Unreviewed
CVE-2025-12405
was published
Nov 10, 2025
A Command Injection vulnerability, resulting from improper file path sanitization (Directory...
High
Unreviewed
CVE-2025-12155
was published
Nov 10, 2025
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration...
High
Unreviewed
CVE-2025-12409
was published
Nov 10, 2025
A SQL injection vulnerability was found in Looker Studio.
A Looker Studio user with report view...
High
Unreviewed
CVE-2025-12397
was published
Nov 10, 2025
A vulnerability was identified in the password generation algorithm when accessing the debug...
High
Unreviewed
CVE-2025-41731
was published
Nov 10, 2025
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection...
High
Unreviewed
CVE-2025-12613
was published
Nov 10, 2025
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The...
High
Unreviewed
CVE-2025-59777
was published
Nov 10, 2025
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The...
High
Unreviewed
CVE-2025-62689
was published
Nov 10, 2025
EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing...
High
Unreviewed
CVE-2025-12867
was published
Nov 10, 2025
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing...
High
Unreviewed
CVE-2025-12865
was published
Nov 10, 2025
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing...
High
Unreviewed
CVE-2025-12864
was published
Nov 10, 2025
A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown...
High
Unreviewed
CVE-2025-12915
was published
Nov 9, 2025
The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary...
High
Unreviewed
CVE-2025-12399
was published
Nov 8, 2025
The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file...
High
Unreviewed
CVE-2025-11967
was published
Nov 8, 2025
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is...
High
Unreviewed
CVE-2025-12099
was published
Nov 8, 2025
ProTip!
Advisories are also available from the
GraphQL API