GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
218 advisories
Filter by severity
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows...
Moderate
Unreviewed
CVE-2020-36924
was published
Jan 6, 2026
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the...
Moderate
Unreviewed
CVE-2020-36905
was published
Jan 6, 2026
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins...
High
Unreviewed
CVE-2020-25788
was published
May 24, 2022
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
Ray has arbitrary code execution via jobs submission API
Critical
CVE-2023-48022
was published
for
ray
(pip)
Nov 28, 2023
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject...
Moderate
Unreviewed
CVE-2025-67842
was published
Dec 19, 2025
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project...
Low
Unreviewed
CVE-2025-68162
was published
Dec 16, 2025
NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
High
Unreviewed
CVE-2025-67900
was published
Dec 15, 2025
Akamai Guardicore Platform Agent before 52.1.1 allows an unprivileged user to fully elevate...
High
Unreviewed
CVE-2025-53841
was published
Dec 3, 2025
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
Critical
CVE-2025-65964
was published
for
n8n
(npm)
Dec 8, 2025
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could...
High
Unreviewed
CVE-2025-33205
was published
Nov 25, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The...
High
Unreviewed
CVE-2024-32011
was published
Nov 11, 2025
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that...
High
Unreviewed
CVE-2021-41841
was published
Feb 10, 2022
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the...
High
Unreviewed
CVE-2021-33626
was published
May 24, 2022
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information...
Critical
Unreviewed
CVE-2024-38476
was published
Jul 1, 2024
An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co....
High
Unreviewed
CVE-2025-41390
was published
Oct 20, 2025
On a client with an admin user, a Global_Shipping script can be implemented. The script could...
High
Unreviewed
CVE-2025-12509
was published
Oct 31, 2025
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
High
CVE-2025-62726
was published
for
n8n
(npm)
Oct 30, 2025
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a...
Critical
Unreviewed
CVE-2025-32463
was published
Jun 30, 2025
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an...
Critical
Unreviewed
CVE-2024-9537
was published
Oct 18, 2024
Kedro allows Remote Code Execution by Pulling Micro Packages
High
CVE-2024-12215
was published
for
kedro
(pip)
Mar 20, 2025
@nx/azure-cache Vulnerable to Build Cache Poisoning via Untrusted Pull Requests
Critical
CVE-2025-36852
was published
for
@nx/azure-cache
(npm)
Jun 10, 2025
Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6...
Low
Unreviewed
CVE-2025-52655
was published
Oct 10, 2025
Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary...
Moderate
Unreviewed
CVE-2025-62186
was published
Oct 7, 2025
ProTip!
Advisories are also available from the
GraphQL API