GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
117 advisories
Filter by severity
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
Critical
CVE-2026-52766
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2025-27462
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2025-27464
was published
Jul 9, 2026
[This CNA information record relates to multiple CVEs; the text explains which aspects...
Critical
Unreviewed
CVE-2025-27463
was published
Jul 9, 2026
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail...
Critical
Unreviewed
CVE-2026-47107
was published
May 19, 2026
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless...
Critical
Unreviewed
CVE-2025-60262
was published
Jan 6, 2026
The `username:password` part was not correctly stripped from URLs in CSP reports potentially...
Critical
Unreviewed
CVE-2025-8031
was published
Jul 22, 2025
A security bypass vulnerability exists in Google Chrome AppBound cookie encryption mechanism due...
Critical
Unreviewed
CVE-2025-34090
was published
Jul 2, 2025
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user...
Critical
Unreviewed
CVE-2014-7210
was published
Jun 26, 2025
Permissions Bypass in Extension Management in Google ChromeOS 16181.27.0 on managed...
Critical
Unreviewed
CVE-2025-6179
was published
Jun 16, 2025
A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected...
Critical
Unreviewed
CVE-2025-40585
was published
Jun 10, 2025
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura...
Critical
Unreviewed
CVE-2025-30465
was published
Apr 1, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5,...
Critical
Unreviewed
CVE-2025-24238
was published
Apr 1, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24207
was published
Apr 1, 2025
An integer overflow was addressed with improved input validation. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24195
was published
Apr 1, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
Critical
Unreviewed
CVE-2025-24172
was published
Apr 1, 2025
HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2025-25535
was published
Mar 26, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27677
was published
Mar 5, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330...
Critical
Unreviewed
CVE-2025-27682
was published
Mar 5, 2025
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an...
Critical
Unreviewed
CVE-2024-56525
was published
Feb 25, 2025
MaysWind ezBookkeeping has Improper Privilege Management
Critical
CVE-2024-57604
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via...
Critical
Unreviewed
CVE-2024-55215
was published
Feb 8, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS...
Critical
Unreviewed
CVE-2025-24174
was published
Jan 28, 2025
CMSimple 5.16 allows the user to edit log.php file via print page.
Critical
Unreviewed
CVE-2024-57548
was published
Jan 28, 2025
This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia...
Critical
Unreviewed
CVE-2025-24135
was published
Jan 28, 2025
ProTip!
Advisories are also available from the
GraphQL API