GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
131,361 advisories
Filter by severity
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
users may append `root` to group listings
Moderate
GHSA-m65q-v92h-cm7q
was published
for
users
(Rust)
Jun 5, 2025
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
Moderate
CVE-2025-48996
was published
for
@haxtheweb/open-apis
(npm)
Jun 5, 2025
SignXML's signature verification with HMAC is vulnerable to an algorithm confusion attack
Moderate
CVE-2025-48994
was published
for
signxml
(pip)
Jun 5, 2025
SignXML's signature verification with HMAC is vulnerable to a timing attack
Moderate
CVE-2025-48995
was published
for
signxml
(pip)
Jun 5, 2025
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected...
Moderate
Unreviewed
CVE-2025-5621
was published
Jun 5, 2025
A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05....
Moderate
Unreviewed
CVE-2025-5620
was published
Jun 5, 2025
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2 and classified as...
Moderate
Unreviewed
CVE-2025-5613
was published
Jun 5, 2025
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass...
Moderate
Unreviewed
CVE-2025-5690
was published
Jun 5, 2025
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified...
Moderate
Unreviewed
CVE-2025-5614
was published
Jun 5, 2025
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as...
Moderate
Unreviewed
CVE-2025-5615
was published
Jun 5, 2025
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2....
Moderate
Unreviewed
CVE-2025-5618
was published
Jun 5, 2025
A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System...
Moderate
Unreviewed
CVE-2025-5617
was published
Jun 5, 2025
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as...
Moderate
Unreviewed
CVE-2025-5616
was published
Jun 5, 2025
Umbraco Vulnerable to By-Pass of Configured Allowed Extensions for File Uploads
Moderate
CVE-2025-48953
was published
for
Umbraco.Cms
(NuGet)
Jun 4, 2025
A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as...
Moderate
Unreviewed
CVE-2025-5612
was published
Jun 4, 2025
A vulnerability, which was classified as critical, was found in CodeAstro Real Estate Management...
Moderate
Unreviewed
CVE-2025-5611
was published
Jun 4, 2025
A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate...
Moderate
Unreviewed
CVE-2025-5610
was published
Jun 4, 2025
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due...
Moderate
Unreviewed
CVE-2025-22244
was published
Jun 4, 2025
A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This...
Moderate
Unreviewed
CVE-2025-5606
was published
Jun 4, 2025
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course...
Moderate
Unreviewed
CVE-2025-46204
was published
Jun 4, 2025
Listmonk v2.4.0 through v4.1.0 is vulnerable to SQL Injection in the QuerySubscribers function...
Moderate
Unreviewed
CVE-2025-46011
was published
Jun 4, 2025
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to...
Moderate
Unreviewed
CVE-2025-22245
was published
Jun 4, 2025
An issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the ...
Moderate
Unreviewed
CVE-2025-46203
was published
Jun 4, 2025
A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-5604
was published
Jun 4, 2025
ProTip!
Advisories are also available from the
GraphQL API