GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,747
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,077 advisories
Filter by severity
A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5552
was published
Jun 4, 2025
A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8....
Moderate
Unreviewed
CVE-2025-5499
was published
Jun 3, 2025
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-5498
was published
Jun 3, 2025
A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been declared as...
Moderate
Unreviewed
CVE-2025-5497
was published
Jun 3, 2025
A malicious user with administrative privileges in the web portal would be able to manipulate the...
Moderate
Unreviewed
CVE-2025-4635
was published
May 30, 2025
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0...
Moderate
Unreviewed
CVE-2025-5326
was published
May 29, 2025
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation...
Moderate
Unreviewed
CVE-2025-33043
was published
May 29, 2025
vLLM Tool Schema allows DoS via Malformed pattern and type Fields
Moderate
CVE-2025-48944
was published
for
vllm
(pip)
May 28, 2025
Laravel Rest Api has a Search Validation Bypass
Moderate
CVE-2025-48490
was published
for
lomkit/laravel-rest-api
(Composer)
May 27, 2025
pypickle unsafe deserialization vulnerability
Moderate
CVE-2025-5174
was published
for
pypickle
(pip)
May 26, 2025
A vulnerability has been found in HumanSignal label-studio-ml-backend up to...
Moderate
Unreviewed
CVE-2025-5173
was published
May 26, 2025
FunAudioLLM InspireMusic deserialization vulnerability
Moderate
CVE-2025-5148
was published
for
inspiremusic
(pip)
May 25, 2025
A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical....
Moderate
Unreviewed
CVE-2025-5114
was published
May 23, 2025
The Intellian C700 web panel allows you to add firewall rules. Each of these rules has an...
Moderate
Unreviewed
CVE-2025-41379
was published
May 23, 2025
The SSID field is not parsed correctly and can be used to inject commands into the hostpad.conf...
Moderate
Unreviewed
CVE-2025-41378
was published
May 23, 2025
Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This...
Moderate
Unreviewed
CVE-2025-3885
was published
May 22, 2025
A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic....
Moderate
Unreviewed
CVE-2025-4905
was published
May 19, 2025
A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to...
Moderate
Unreviewed
CVE-2025-4742
was published
May 16, 2025
A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic....
Moderate
Unreviewed
CVE-2025-4740
was published
May 16, 2025
A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up...
Moderate
Unreviewed
CVE-2025-4701
was published
May 15, 2025
Jenkins DingTalk Plugin Unconditionally Disables SSL/TLS Certificate and Hostname Validation
Moderate
CVE-2025-47888
was published
for
io.jenkins.plugins:dingding-notifications
(Maven)
May 14, 2025
Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel...
Moderate
Unreviewed
CVE-2025-20034
was published
May 13, 2025
Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to...
Moderate
Unreviewed
CVE-2025-20031
was published
May 13, 2025
Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server...
Moderate
Unreviewed
CVE-2025-20009
was published
May 13, 2025
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized...
Moderate
Unreviewed
CVE-2025-29968
was published
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API