GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,731
Erlang
35
GitHub Actions
29
Go
2,308
Maven
5,000+
npm
3,949
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
121,039 advisories
Filter by severity
A vulnerability, which was classified as problematic, has been found in fossasia open-event...
Moderate
Unreviewed
CVE-2025-5323
was published
May 29, 2025
Buffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of...
Moderate
Unreviewed
CVE-2025-29632
was published
May 29, 2025
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail...
Moderate
Unreviewed
CVE-2025-3913
was published
May 29, 2025
HuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of...
Moderate
Unreviewed
CVE-2025-46078
was published
May 29, 2025
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability...
Moderate
Unreviewed
CVE-2025-5321
was published
May 29, 2025
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation...
Moderate
Unreviewed
CVE-2025-33043
was published
May 29, 2025
HuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass...
Moderate
Unreviewed
CVE-2025-46080
was published
May 29, 2025
Use of entitlement "com.apple.security.cs.disable-library-validation" and lack of launch and...
Moderate
Unreviewed
CVE-2025-4081
was published
May 29, 2025
yasm commit 9defefae was discovered to contain a NULL pointer dereference via the...
Moderate
Unreviewed
CVE-2024-22653
was published
May 29, 2025
A vulnerability classified as problematic has been found in gradio-app gradio up to 5.29.1. This...
Moderate
Unreviewed
CVE-2025-5320
was published
May 29, 2025
An authenticated user can disclose the cleartext password of a configured SMTP server via an HTTP...
Moderate
Unreviewed
CVE-2025-48046
was published
May 29, 2025
The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-5122
was published
May 29, 2025
The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress...
Moderate
Unreviewed
CVE-2025-4670
was published
May 29, 2025
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-5286
was published
May 29, 2025
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-4583
was published
May 29, 2025
CVE-2025-27706 is a cross-site scripting vulnerability in the management
console of Absolute...
Moderate
Unreviewed
CVE-2025-27706
was published
May 28, 2025
CVE-2025-27702 is a vulnerability in the management console of Absolute
Secure Access prior to...
Moderate
Unreviewed
CVE-2025-27702
was published
May 28, 2025
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v...
Moderate
Unreviewed
CVE-2025-48747
was published
May 28, 2025
In some cases, Kea log files or lease files may be world-readable.
This issue affects Kea...
Moderate
Unreviewed
CVE-2025-32803
was published
May 28, 2025
Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component...
Moderate
Unreviewed
CVE-2025-1461
was published
May 28, 2025
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap...
Moderate
Unreviewed
CVE-2025-48927
was published
May 28, 2025
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to...
Moderate
Unreviewed
CVE-2025-48925
was published
May 28, 2025
Kea configuration and API directives can be used to overwrite arbitrary files, subject to...
Moderate
Unreviewed
CVE-2025-32802
was published
May 28, 2025
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover...
Moderate
Unreviewed
CVE-2025-48926
was published
May 28, 2025
The TeleMessage service through 2025-05-05 implements authentication through a long-lived...
Moderate
Unreviewed
CVE-2025-48929
was published
May 28, 2025
ProTip!
Advisories are also available from the
GraphQL API