GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,634 advisories
Filter by severity
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions...
Critical
Unreviewed
CVE-2025-25037
was published
Jun 20, 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is...
Low
Unreviewed
CVE-2025-6199
was published
Jun 17, 2025
A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not...
Moderate
Unreviewed
CVE-2025-49177
was published
Jun 17, 2025
The created backup files are unencrypted, making the application vulnerable for gathering...
Moderate
Unreviewed
CVE-2025-49200
was published
Jun 12, 2025
A remote unauthorized attacker may gather sensitive information of the application, due to...
High
Unreviewed
CVE-2025-49184
was published
Jun 12, 2025
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions...
Moderate
Unreviewed
CVE-2025-4798
was published
Jun 11, 2025
In Apache CloudStack, a flaw in access control affects the listTemplates and listIsos APIs. A...
Moderate
Unreviewed
CVE-2025-30675
was published
Jun 11, 2025
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the...
High
Unreviewed
CVE-2025-26521
was published
Jun 11, 2025
Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an...
Moderate
Unreviewed
CVE-2025-43579
was published
Jun 10, 2025
Nautobot may allows uploaded media files to be accessible without authentication
Moderate
CVE-2025-49143
was published
for
nautobot
(pip)
Jun 10, 2025
Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized...
Moderate
Unreviewed
CVE-2025-47969
was published
Jun 10, 2025
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS...
Moderate
Unreviewed
CVE-2025-25250
was published
Jun 10, 2025
GWC Home Page communicate version and revision information
Moderate
CVE-2024-38524
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an...
Moderate
Unreviewed
CVE-2025-40662
was published
Jun 10, 2025
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
High
CVE-2025-49653
was published
for
backend.ai
(pip)
Jun 9, 2025
The AuthPolicy metadata on Red Hat Connectivity Link contains an object which stores secretes,...
Moderate
Unreviewed
CVE-2025-25209
was published
Jun 9, 2025
Exposure of sensitive information to an unauthorized actor in Power Automate allows an...
Critical
Unreviewed
CVE-2025-47966
was published
Jun 5, 2025
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
PostgreSQL Anonymizer v2.0 and v2.1 contain a vulnerability that allows a masked user to bypass...
Moderate
Unreviewed
CVE-2025-5690
was published
Jun 5, 2025
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP),...
Moderate
Unreviewed
CVE-2025-20129
was published
Jun 4, 2025
A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic....
Moderate
Unreviewed
CVE-2025-5436
was published
Jun 2, 2025
The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms...
Moderate
Unreviewed
CVE-2025-4659
was published
May 30, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-31231
was published
May 30, 2025
ProTip!
Advisories are also available from the
GraphQL API