GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user...
Moderate
Unreviewed
CVE-2023-4194
was published
Aug 7, 2023
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users...
Moderate
Unreviewed
CVE-2024-0387
was published
Feb 26, 2024
Liferay Portal and Liferay DXP HTTP Header Can Expose Versions
Moderate
CVE-2024-26267
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Microsoft ACI Confidential Containers Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2026-26122
was published
Mar 6, 2026
A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of...
Moderate
Unreviewed
CVE-2026-2617
was published
Feb 17, 2026
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all...
Moderate
Unreviewed
CVE-2026-1675
was published
Feb 7, 2026
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
Moderate
CVE-2025-66482
was published
for
misskey-js
(npm)
Dec 15, 2025
Incorrect configuration of replication security in the MariaDB component of the infra-operator in...
Moderate
Unreviewed
CVE-2025-14758
was published
Dec 16, 2025
In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and...
Moderate
Unreviewed
CVE-2025-64781
was published
Dec 12, 2025
The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers...
Moderate
Unreviewed
CVE-2025-52622
was published
Dec 2, 2025
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix the smbd_response...
Moderate
Unreviewed
CVE-2025-38523
was published
Aug 16, 2025
Jenkins Eggplant Runner Plugin protection mechanism disabled
Moderate
CVE-2025-64135
was published
for
io.jenkins.plugins:eggplant-runner
(Maven)
Oct 29, 2025
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation...
Moderate
Unreviewed
CVE-2022-47196
was published
Jan 19, 2023
An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation...
Moderate
Unreviewed
CVE-2022-47194
was published
Jan 19, 2023
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value,...
Moderate
Unreviewed
CVE-2020-11917
was published
Nov 7, 2024
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker...
Moderate
Unreviewed
CVE-2025-35021
was published
Nov 4, 2025
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap...
Moderate
Unreviewed
CVE-2025-48927
was published
May 28, 2025
In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Fix...
Moderate
Unreviewed
CVE-2022-49099
was published
Oct 14, 2025
Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user...
Moderate
Unreviewed
CVE-2024-9949
was published
Oct 23, 2024
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with...
Moderate
Unreviewed
CVE-2025-41245
was published
Sep 29, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
During a short time frame while the device is booting an unauthenticated remote attacker can send...
Moderate
Unreviewed
CVE-2025-41713
was published
Sep 15, 2025
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept...
Moderate
Unreviewed
CVE-2025-32330
was published
Sep 4, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
In the Linux kernel, the following vulnerability has been resolved:
dm btree remove: assign...
Moderate
Unreviewed
CVE-2021-47343
was published
May 21, 2024
ProTip!
Advisories are also available from the
GraphQL API