GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara...
Moderate
Unreviewed
CVE-2025-3941
was published
May 22, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-48136
was published
May 16, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30849
was published
Apr 1, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30870
was published
Apr 1, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Moderate
CVE-2025-29914
was published
for
github.com/corazawaf/coraza/v3
(Go)
Mar 20, 2025
Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via...
Moderate
Unreviewed
CVE-2024-57785
was published
Jan 17, 2025
An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online...
Moderate
Unreviewed
CVE-2024-55058
was published
Dec 17, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53739
was published
Nov 30, 2024
gitsign may use incorrect Rekor entries during verification
Low
CVE-2024-51746
was published
for
github.com/sigstore/gitsign
(Go)
Nov 5, 2024
gix-path uses local config across repos when it is the highest scope
Low
CVE-2024-45305
was published
for
gix-path
(Rust)
Sep 3, 2024
Nuxt vulnerable to remote code execution via the browser when running the test locally
Critical
CVE-2024-34344
was published
for
nuxt
(npm)
Aug 5, 2024
TorchServe vulnerable to bypass of allowed_urls configuration
Critical
CVE-2024-35198
was published
for
torchserve
(pip)
Jul 18, 2024
The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all...
High
Unreviewed
CVE-2024-4887
was published
Jun 7, 2024
In the Linux kernel, the following vulnerability has been resolved:
IB/mlx5: Fix initializing CQ...
High
Unreviewed
CVE-2021-47261
was published
May 21, 2024
In the Linux kernel, the following vulnerability has been resolved:
ftrace: Do not blindly read...
Moderate
Unreviewed
CVE-2021-47276
was published
May 21, 2024
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2023-42125
was published
May 3, 2024
Directus has MySQL accent insensitive email matching
High
CVE-2024-27295
was published
for
directus
(npm)
Mar 1, 2024
Docassemble unauthorized access through URL manipulation
High
CVE-2024-27292
was published
for
docassemble.base
(pip)
Feb 29, 2024
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
High
CVE-2023-34092
was published
for
vite
(npm)
Jun 6, 2023
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model...
Critical
Unreviewed
CVE-2023-31814
was published
May 23, 2023
lambdaisland/uri `authority-regex` returns the wrong authority
Moderate
CVE-2023-28628
was published
for
lambdaisland:uri
(Maven)
Mar 27, 2023
Opencontainers runc Incorrect Authorization vulnerability
High
CVE-2023-27561
was published
for
github.com/opencontainers/runc
(Go)
Mar 3, 2023
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version...
Critical
Unreviewed
CVE-2021-37315
was published
Feb 3, 2023
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of...
Critical
Unreviewed
CVE-2022-30257
was published
Nov 22, 2022
An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of...
Critical
Unreviewed
CVE-2022-30258
was published
Nov 22, 2022
ProTip!
Advisories are also available from the
GraphQL API