GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
280,576 advisories
Filter by severity
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Moderate
CVE-2025-35036
was published
for
org.hibernate.validator:hibernate-validator
(Maven)
Jun 3, 2025
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
Auth0 Wordpress Plugin vulnerable to Deserialization of Untrusted Data
Critical
GHSA-862m-5253-832r
was published
for
auth0/wordpress
(Composer)
Jun 5, 2025
users may append `root` to group listings
Moderate
GHSA-m65q-v92h-cm7q
was published
for
users
(Rust)
Jun 5, 2025
Multer vulnerable to Denial of Service via unhandled exception
High
CVE-2025-48997
was published
for
multer
(npm)
Jun 5, 2025
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
Moderate
CVE-2025-48996
was published
for
@haxtheweb/open-apis
(npm)
Jun 5, 2025
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
High
CVE-2025-3260
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
anon-vec lacks sufficient checks in public API
Low
GHSA-pr59-jjr4-gcf6
was published
for
anon-vec
(Rust)
Jun 5, 2025
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Moderate
CVE-2025-48994
was published
for
signxml
(pip)
Jun 5, 2025
SignXML's signature verification with HMAC is vulnerable to a timing attack
Moderate
CVE-2025-48995
was published
for
signxml
(pip)
Jun 5, 2025
Aim Vulnerable to Sandbox Escape Leading to Remote Code Execution
Low
CVE-2025-5321
was published
for
aim
(pip)
May 29, 2025
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution ...
High
Unreviewed
CVE-2024-22903
was published
Feb 2, 2024
In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior,...
Low
Unreviewed
CVE-2020-14477
was published
May 24, 2022
Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly...
Low
Unreviewed
CVE-2020-16241
was published
May 24, 2022
Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system...
Low
Unreviewed
CVE-2020-12023
was published
May 24, 2022
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product exposes a...
High
Unreviewed
CVE-2020-16247
was published
May 24, 2022
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. When an attacker claims to...
Moderate
Unreviewed
CVE-2020-16198
was published
May 24, 2022
Philips SureSigns VS4, A.07.107 and prior. The product receives input or data, but it does not...
Low
Unreviewed
CVE-2020-16237
was published
May 24, 2022
Philips SureSigns VS4, A.07.107 and prior. When an actor claims to have a given identity, the...
Moderate
Unreviewed
CVE-2020-16239
was published
May 24, 2022
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not...
Low
Unreviewed
CVE-2020-14525
was published
May 24, 2022
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-5621
was published
Jun 5, 2025
A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by...
Critical
Unreviewed
CVE-2025-5622
was published
Jun 5, 2025
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This...
High
Unreviewed
CVE-2025-5619
was published
Jun 5, 2025
A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This...
Critical
Unreviewed
CVE-2025-5623
was published
Jun 5, 2025
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05....
Moderate
Unreviewed
CVE-2025-5620
was published
Jun 5, 2025
ProTip!
Advisories are also available from the
GraphQL API