GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,417
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
37 advisories
Filter by severity
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the...
Low
Unreviewed
CVE-2025-54956
was published
Aug 3, 2025
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts...
Low
Unreviewed
CVE-2025-54352
was published
Jul 21, 2025
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL...
Moderate
Unreviewed
CVE-2025-54310
was published
Jul 18, 2025
An unauthenticated remote attacker could use a demo account of the portal to hijack devices that...
High
Unreviewed
CVE-2025-41645
was published
May 13, 2025
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX...
Moderate
Unreviewed
CVE-2017-14013
was published
May 13, 2022
In the Linux kernel, the following vulnerability has been resolved:
s390/pkey: Use...
Moderate
Unreviewed
CVE-2024-42158
was published
Jul 30, 2024
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of...
High
Unreviewed
CVE-2023-44100
was published
Oct 11, 2023
Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of...
High
Unreviewed
CVE-2023-44104
was published
Oct 11, 2023
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300....
High
Unreviewed
CVE-2023-31115
was published
Jun 7, 2023
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300....
Critical
Unreviewed
CVE-2023-31114
was published
Jun 7, 2023
An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in...
Moderate
Unreviewed
CVE-2023-22950
was published
Apr 13, 2023
PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
Critical
Unreviewed
CVE-2022-4446
was published
Dec 13, 2022
Newgen OmniFlow Intelligent Business Process Suite (iBPS) 7.0 has an "improper server side...
High
Unreviewed
CVE-2018-17791
was published
May 24, 2022
SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without...
High
Unreviewed
CVE-2019-1020011
was published
May 24, 2022
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV)...
High
Unreviewed
CVE-2012-2979
was published
Apr 23, 2022
An issue was discovered in apply.cgi on D-Link DAP-1520 devices before 1.10b04Beta02. Whenever a...
High
Unreviewed
CVE-2020-15892
was published
May 24, 2022
D-link DIR-825AC G1 devices have Insufficient Compartmentalization between a host network and a...
High
Unreviewed
CVE-2019-13263
was published
May 24, 2022
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is...
High
Unreviewed
CVE-2019-11770
was published
May 24, 2022
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data...
High
Unreviewed
CVE-2021-22806
was published
Feb 12, 2022
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management...
Critical
Unreviewed
CVE-2022-20658
was published
Jan 15, 2022
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability....
High
Unreviewed
CVE-2021-36338
was published
Jan 22, 2022
In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can...
Moderate
Unreviewed
CVE-2021-34574
was published
May 24, 2022
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote...
Moderate
Unreviewed
CVE-2002-0055
was published
Apr 30, 2022
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent...
Moderate
Unreviewed
CVE-2004-0872
was published
Apr 29, 2022
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low...
High
Unreviewed
CVE-2021-24602
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API