GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
280,576 advisories
Filter by severity
ingress-nginx admission controller RCE escalation
Critical
CVE-2025-1974
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126...
Moderate
Unreviewed
CVE-2025-2717
was published
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized mirror annotations
High
CVE-2025-1098
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - auth secret file path traversal vulnerability
Moderate
CVE-2025-24513
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
OpenDaylight SFC Denial of Service (DoS)
High
CVE-2025-29313
was published
for
org.opendaylight.sfc:odl-sfc-openflow-renderer
(Maven)
Mar 24, 2025
OpenDaylight SFC Insecure Shiro Cookie Configuration
High
CVE-2025-29314
was published
for
org.opendaylight.sfc:odl-sfc-openflow-renderer
(Maven)
Mar 24, 2025
OpenDaylight SFC Allows Unauthorized Privileged Execution via Crafted Request
Critical
CVE-2025-29315
was published
for
org.opendaylight.sfc:sfc-parent
(Maven)
Mar 24, 2025
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue...
Moderate
Unreviewed
CVE-2025-2710
was published
Mar 24, 2025
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-2711
was published
Mar 24, 2025
Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private...
High
Unreviewed
CVE-2025-29311
was published
Mar 24, 2025
An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected...
Critical
Unreviewed
CVE-2025-29312
was published
Mar 24, 2025
PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2025-2231
was published
Mar 24, 2025
A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this...
Moderate
Unreviewed
CVE-2025-2706
was published
Mar 24, 2025
A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-2709
was published
Mar 24, 2025
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1...
Moderate
Unreviewed
CVE-2025-2708
was published
Mar 24, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2746
was published
Mar 24, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2747
was published
Mar 24, 2025
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging...
High
Unreviewed
CVE-2025-2749
was published
Mar 24, 2025
Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via...
Critical
Unreviewed
CVE-2025-29100
was published
Mar 24, 2025
A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to...
Critical
Unreviewed
CVE-2025-29135
was published
Mar 24, 2025
An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when...
Critical
Unreviewed
CVE-2025-29310
was published
Mar 24, 2025
A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro...
Moderate
Unreviewed
CVE-2025-2707
was published
Mar 24, 2025
The Kentico Xperience application does not fully validate or filter files uploaded via the...
Moderate
Unreviewed
CVE-2025-2748
was published
Mar 24, 2025
Web Push Denial of Service via malicious Web Push endpoint
Moderate
GHSA-fc83-9jwq-gc2m
was published
for
web-push
(Rust)
Mar 24, 2025
Cilium node based network policies may incorrectly allow workload traffic
Low
CVE-2025-30163
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Mar 24, 2025
ProTip!
Advisories are also available from the
GraphQL API