GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
110,144 advisories
Filter by severity
Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-8653
was published
Aug 6, 2025
Out-of-bounds write vulnerability in the skia module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2025-54627
was published
Aug 6, 2025
Vulnerability of improper processing of abnormal conditions in huge page separation.
Impact:...
High
Unreviewed
CVE-2025-54634
was published
Aug 6, 2025
Binding authentication bypass vulnerability in the devicemanager module.
Impact: Successful...
High
Unreviewed
CVE-2025-54622
was published
Aug 6, 2025
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title...
High
Unreviewed
CVE-2025-7036
was published
Aug 6, 2025
EXTRA_REFERRER resource read vulnerability in the Gallery module.
Impact: Successful exploitation...
High
Unreviewed
CVE-2025-54611
was published
Aug 6, 2025
Authentication management vulnerability in the ArkWeb module.
Impact: Successful exploitation of...
High
Unreviewed
CVE-2025-54607
was published
Aug 6, 2025
Status verification vulnerability in the lock screen module.
Impact: Successful exploitation of...
High
Unreviewed
CVE-2025-54606
was published
Aug 6, 2025
Race condition vulnerability in the virtualization base module. Successful exploitation of this...
High
Unreviewed
CVE-2025-54655
was published
Aug 6, 2025
Path traversal vulnerability in the virtualization base module. Successful exploitation of this...
High
Unreviewed
CVE-2025-54652
was published
Aug 6, 2025
Path traversal vulnerability in the virtualization file module. Successful exploitation of this...
High
Unreviewed
CVE-2025-54653
was published
Aug 6, 2025
Maxthon3 versions prior to 3.3 are vulnerable to cross context scripting (XCS) via the about...
High
Unreviewed
CVE-2012-10032
was published
Aug 5, 2025
BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to...
High
Unreviewed
CVE-2012-10031
was published
Aug 5, 2025
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of...
High
Unreviewed
CVE-2012-10034
was published
Aug 5, 2025
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative...
High
Unreviewed
CVE-2012-10028
was published
Aug 5, 2025
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A...
High
Unreviewed
CVE-2013-10065
was published
Aug 5, 2025
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command...
High
Unreviewed
CVE-2012-10029
was published
Aug 5, 2025
XBMC version 11, including builds up to the 2012-11-04 nightly release, contains a path traversal...
High
Unreviewed
CVE-2012-10024
was published
Aug 5, 2025
Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa...
High
Unreviewed
CVE-2025-51628
was published
Aug 5, 2025
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of...
High
Unreviewed
CVE-2025-54254
was published
Aug 5, 2025
Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker...
High
Unreviewed
CVE-2025-7674
was published
Aug 5, 2025
Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection....
High
Unreviewed
CVE-2025-43978
was published
Aug 5, 2025
An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated...
High
Unreviewed
CVE-2025-43979
was published
Aug 5, 2025
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
High
CVE-2025-54125
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
XWiki leaks password hashes and other accessible password properties
High
CVE-2025-54124
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
ProTip!
Advisories are also available from the
GraphQL API