GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
371 advisories
Filter by severity
Apache Druid: Users can provide MySQL JDBC properties not on allow list
Low
CVE-2024-45537
was published
for
org.apache.druid:druid
(Maven)
Sep 17, 2024
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
Low
Unreviewed
CVE-2024-43697
was published
Oct 8, 2024
CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft...
Low
Unreviewed
CVE-2024-8518
was published
Oct 8, 2024
Symfony has an incorrect response from Validator when input ends with `\n`
Low
CVE-2024-50343
was published
for
symfony/symfony
(Composer)
Nov 6, 2024
Ansible-Core vulnerable to content protections bypass
Low
CVE-2024-11079
was published
for
ansible-core
(pip)
Nov 12, 2024
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All...
Low
Unreviewed
CVE-2024-50560
was published
Nov 12, 2024
Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an...
Low
Unreviewed
CVE-2024-32485
was published
Nov 13, 2024
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon...
Low
Unreviewed
CVE-2024-22117
was published
Nov 26, 2024
sigstore-java has a vulnerability with bundle verification
Low
CVE-2024-54140
was published
for
dev.sigstore:sigstore-java
(Maven)
Dec 5, 2024
Insufficient validation of filenames against control characters in Apache Subversion repositories...
Low
Unreviewed
CVE-2024-46901
was published
Dec 9, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-52831
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-43755
was published
Dec 11, 2024
sigstore has insufficient validation of integration timestamp during verification
Low
CVE-2024-55655
was published
for
sigstore
(pip)
Dec 11, 2024
Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer...
Low
Unreviewed
CVE-2024-12014
was published
Dec 20, 2024
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts...
Low
Unreviewed
CVE-2024-42175
was published
Jan 11, 2025
A vulnerability, which was classified as critical, has been found in MaxD Lightning Module 4.43...
Low
Unreviewed
CVE-2025-0974
was published
Feb 3, 2025
Keycloak allows cross-site scripting (XSS)
Low
CVE-2024-4028
was published
for
org.keycloak:keycloak-core
(Maven)
Feb 18, 2025
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Low
CVE-2025-29923
was published
for
github.com/redis/go-redis/v9
(Go)
Mar 20, 2025
Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna...
Low
Unreviewed
CVE-2025-4762
was published
May 15, 2025
Spring Framework DataBinder Case Sensitive Match Exception
Low
CVE-2025-22233
was published
for
org.springframework:spring-context
(Maven)
May 16, 2025
anon-vec lacks sufficient checks in public API
Low
GHSA-pr59-jjr4-gcf6
was published
for
anon-vec
(Rust)
Jun 5, 2025
ProTip!
Advisories are also available from the
GraphQL API