GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
304 advisories
Filter by severity
Apache Knox allows impersonation of users
Moderate
CVE-2017-5646
was published
for
org.apache.knox:gateway-provider-identity-assertion-common
(Maven)
May 13, 2022
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local...
Moderate
Unreviewed
CVE-2025-43929
was published
Apr 20, 2025
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with...
Critical
Unreviewed
CVE-2017-6519
was published
May 13, 2022
Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below...
Critical
Unreviewed
CVE-2025-3651
was published
Apr 17, 2025
When viewing an email message A, which contains an attached message B, where B is encrypted or...
Moderate
Unreviewed
CVE-2022-1520
was published
Dec 22, 2022
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have...
Moderate
Unreviewed
CVE-2022-22757
was published
Dec 22, 2022
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking...
High
Unreviewed
CVE-2022-42927
was published
Dec 22, 2022
The Performance API did not properly hide the fact whether a request cross-origin resource has...
Moderate
Unreviewed
CVE-2022-29915
was published
Dec 22, 2022
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a...
Moderate
Unreviewed
CVE-2025-3071
was published
Apr 2, 2025
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
High
Unreviewed
CVE-2021-33959
was published
Jan 18, 2023
Ollama DNS rebinding vulnerability
High
CVE-2024-28224
was published
for
github.com/ollama/ollama
(Go)
Apr 8, 2024
An intent redriction vulnerability exists in the Xiaomi quick App framework application product....
Moderate
Unreviewed
CVE-2024-45353
was published
Mar 27, 2025
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is...
Moderate
Unreviewed
CVE-2024-45354
was published
Mar 27, 2025
An code execution vulnerability exists in the Xiaomi smarthome application product. The...
High
Unreviewed
CVE-2024-45352
was published
Mar 27, 2025
Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
High
CVE-2024-8183
was published
for
prefect
(pip)
Mar 20, 2025
Feast Cross-Origin Resource Sharing vulnerability
High
CVE-2024-11602
was published
for
feast
(pip)
Mar 20, 2025
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0...
Moderate
Unreviewed
CVE-2023-0132
was published
Jan 10, 2023
AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
High
CVE-2024-8487
was published
for
agentscope
(pip)
Mar 20, 2025
A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive...
High
Unreviewed
CVE-2024-7819
was published
Mar 20, 2025
A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This...
High
Unreviewed
CVE-2024-8024
was published
Mar 20, 2025
Gin mishandles a wildcard at the end of an origin string
Critical
CVE-2019-25211
was published
for
github.com/gin-contrib/cors
(Go)
Jun 29, 2024
An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious...
Moderate
Unreviewed
CVE-2025-23117
was published
Mar 1, 2025
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or...
Moderate
Unreviewed
CVE-2025-1102
was published
Feb 12, 2025
esbuild enables any website to send any requests to the development server and read the response
Moderate
GHSA-67mh-4wv8-2f99
was published
for
esbuild
(npm)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API