GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
100,107 advisories
Filter by severity
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This...
High
Unreviewed
CVE-2025-5785
was published
Jun 6, 2025
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical....
High
Unreviewed
CVE-2025-5787
was published
Jun 6, 2025
WOLFBOX Level 2 EV Charger LAN OTA Exposed Dangerous Method Remote Code Execution Vulnerability....
High
Unreviewed
CVE-2025-5748
was published
Jun 6, 2025
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as...
High
Unreviewed
CVE-2025-5786
was published
Jun 6, 2025
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical....
High
Unreviewed
CVE-2025-5788
was published
Jun 6, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-22484
was published
Jun 6, 2025
An improper certificate validation vulnerability has been reported to affect File Station 5. If...
High
Unreviewed
CVE-2025-22486
was published
Jun 6, 2025
A command injection vulnerability has been reported to affect several QNAP operating system...
High
Unreviewed
CVE-2025-22481
was published
Jun 6, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
High
Unreviewed
CVE-2025-29872
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage...
High
Unreviewed
CVE-2025-49453
was published
Jun 6, 2025
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the...
High
Unreviewed
CVE-2025-5806
was published
Jun 6, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-49421
was published
Jun 6, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-49327
was published
Jun 6, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-49326
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Adrian Hanft Konami Easter Egg allows Stored...
High
Unreviewed
CVE-2025-49425
was published
Jun 6, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-49328
was published
Jun 6, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-49313
was published
Jun 6, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-49323
was published
Jun 6, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-49315
was published
Jun 6, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-49308
was published
Jun 6, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-49307
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-49262
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light allows Stored...
High
Unreviewed
CVE-2025-30995
was published
Jun 6, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-30999
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor allows Path Traversal. This...
High
Unreviewed
CVE-2025-49237
was published
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API