GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple...
Moderate
Unreviewed
CVE-2021-42205
was published
Nov 7, 2022
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests...
Moderate
Unreviewed
CVE-2022-34472
was published
Dec 22, 2022
When run on commands with certain arguments set, explain may fail to validate these arguments...
Moderate
Unreviewed
CVE-2025-3084
was published
Apr 1, 2025
A vulnerability has been found in Dahua products. After
obtaining the administrator's username...
Moderate
Unreviewed
CVE-2024-39945
was published
Jul 31, 2024
ntpd NTS client denial of service via wrongly sized cookies
Moderate
GHSA-v83q-83hj-rw38
was published
for
ntpd
(Rust)
Feb 28, 2025
printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does...
Moderate
Unreviewed
CVE-2024-25741
was published
Feb 12, 2024
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable...
Moderate
Unreviewed
CVE-2023-21026
was published
Mar 24, 2023
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the...
Moderate
Unreviewed
CVE-2023-21036
was published
Mar 24, 2023
CometBFT allows a malicious peer to make node stuck in blocksync
Moderate
CVE-2025-24371
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue...
Moderate
Unreviewed
CVE-2024-55548
was published
Dec 10, 2024
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
Moderate
Unreviewed
CVE-2024-9104
was published
Oct 16, 2024
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22...
Moderate
Unreviewed
CVE-2024-22023
was published
Apr 4, 2024
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to...
Moderate
Unreviewed
CVE-2023-39136
was published
Aug 31, 2023
HashiCorpVault does not correctly validate OCSP responses
Moderate
CVE-2024-2660
was published
for
github.com/hashicorp/vault
(Go)
Apr 4, 2024
A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct...
Moderate
Unreviewed
CVE-2023-5090
was published
Nov 6, 2023
A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All...
Moderate
Unreviewed
CVE-2024-37992
was published
Sep 10, 2024
CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional...
Moderate
Unreviewed
CVE-2024-38482
was published
Aug 2, 2024
Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow...
Moderate
Unreviewed
CVE-2024-38435
was published
Jul 21, 2024
IBM Security Verify Access 10.0.0.0 through 10.0.7.1, under certain configurations, could allow...
Moderate
Unreviewed
CVE-2024-31883
was published
Jun 27, 2024
Kubelet Incorrect Privilege Assignment
Moderate
CVE-2019-11245
was published
for
k8s.io/kubernetes/cmd/kubelet
(Go)
Apr 24, 2024
vitess allows users to create keyspaces that can deny access to already existing keyspaces
Moderate
CVE-2023-29194
was published
for
vitess.io/vitess
(Go)
Apr 11, 2023
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding...
Moderate
Unreviewed
CVE-2024-21593
was published
Apr 12, 2024
An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet...
Moderate
Unreviewed
CVE-2024-26007
was published
May 14, 2024
An Improper Check or Handling of Exceptional Conditions vulnerability in the Packet Forwarding...
Moderate
Unreviewed
CVE-2023-44203
was published
Oct 13, 2023
An Improper Check or Handling of Exceptional Conditions vulnerability in the Layer-2 control...
Moderate
Unreviewed
CVE-2023-36849
was published
Jul 14, 2023
ProTip!
Advisories are also available from the
GraphQL API