GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,730
Erlang
35
GitHub Actions
29
Go
2,307
Maven
5,000+
npm
3,947
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
69 advisories
Filter by severity
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling...
High
Unreviewed
CVE-2022-41589
was published
Oct 14, 2022
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple...
Moderate
Unreviewed
CVE-2021-42205
was published
Nov 7, 2022
Vyper Does Not Check the Success of Certain Precompile Calls
Low
CVE-2025-21607
was published
for
vyper
(pip)
Jan 14, 2025
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests...
Moderate
Unreviewed
CVE-2022-34472
was published
Dec 22, 2022
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It...
High
Unreviewed
CVE-2024-47215
was published
Apr 3, 2025
When run on commands with certain arguments set, explain may fail to validate these arguments...
Moderate
Unreviewed
CVE-2025-3084
was published
Apr 1, 2025
A vulnerability has been found in Dahua products. After
obtaining the administrator's username...
Moderate
Unreviewed
CVE-2024-39945
was published
Jul 31, 2024
The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a...
High
Unreviewed
CVE-2024-50954
was published
Jan 15, 2025
ntpd NTS client denial of service via wrongly sized cookies
Moderate
GHSA-v83q-83hj-rw38
was published
for
ntpd
(Rust)
Feb 28, 2025
printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does...
Moderate
Unreviewed
CVE-2024-25741
was published
Feb 12, 2024
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable...
Moderate
Unreviewed
CVE-2023-21026
was published
Mar 24, 2023
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the...
Moderate
Unreviewed
CVE-2023-21036
was published
Mar 24, 2023
CometBFT allows a malicious peer to make node stuck in blocksync
Moderate
CVE-2025-24371
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Lodestar snappy decompression issue
Low
GHSA-53rv-hcvm-rpp9
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
notation-go has an OS error when setting CRL cache leads to denial of signature verification
Low
CVE-2024-51491
was published
for
github.com/notaryproject/notation-go
(Go)
Jan 13, 2025
Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue...
Moderate
Unreviewed
CVE-2024-55548
was published
Dec 10, 2024
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-10781
was published
Nov 26, 2024
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could...
High
Unreviewed
CVE-2023-34348
was published
Jan 18, 2024
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
Moderate
Unreviewed
CVE-2024-9104
was published
Oct 16, 2024
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22...
Moderate
Unreviewed
CVE-2024-22023
was published
Apr 4, 2024
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x)...
High
Unreviewed
CVE-2024-22052
was published
Apr 4, 2024
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
22.x) and Ivanti...
High
Unreviewed
CVE-2024-22053
was published
Apr 4, 2024
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti...
High
Unreviewed
CVE-2024-21894
was published
Apr 5, 2024
Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola...
High
Unreviewed
CVE-2023-23774
was published
Aug 29, 2023
An unhandled edge case in the component _sanitizedPath of ZipArchive v2.5.4 allows attackers to...
Moderate
Unreviewed
CVE-2023-39136
was published
Aug 31, 2023
ProTip!
Advisories are also available from the
GraphQL API