GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,904
Erlang
38
GitHub Actions
38
Go
2,566
Maven
5,000+
npm
4,237
NuGet
753
pip
4,001
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
79 advisories
Filter by severity
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a...
High
Unreviewed
CVE-2025-62585
was published
Oct 16, 2025
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab...
Critical
Unreviewed
CVE-2025-62583
was published
Oct 16, 2025
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiProxy 7.6.0...
Moderate
Unreviewed
CVE-2025-25255
was published
Oct 14, 2025
HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result...
Moderate
Unreviewed
CVE-2025-31969
was published
Oct 12, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43262
was published
Sep 16, 2025
Java: DoS Vulnerability in JSON-JAVA
High
CVE-2023-5072
was published
for
org.json:json
(Maven)
Nov 14, 2023
Improperly implemented security check for standard in the DDRIO configuration for some Intel(R)...
Moderate
Unreviewed
CVE-2025-32086
was published
Aug 12, 2025
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
Moderate
Unreviewed
CVE-2021-42017
was published
Mar 9, 2022
A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179....
Low
Unreviewed
CVE-2025-8204
was published
Jul 26, 2025
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox...
Moderate
Unreviewed
CVE-2021-26105
was published
Mar 24, 2025
An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version...
Moderate
Unreviewed
CVE-2024-55599
was published
Jul 8, 2025
SpiceDB checks involving relations with caveats can result in no permission when permission is expected
Low
CVE-2025-49011
was published
for
github.com/authzed/spicedb
(Go)
Jun 6, 2025
SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which...
High
Unreviewed
CVE-2022-38732
was published
Sep 30, 2022
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus...
Moderate
Unreviewed
CVE-2017-6032
was published
May 13, 2022
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss...
Moderate
Unreviewed
CVE-2021-26328
was published
Jan 11, 2023
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a...
High
Unreviewed
CVE-2025-3069
was published
Apr 2, 2025
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6...
Moderate
Unreviewed
CVE-2020-9295
was published
Mar 17, 2025
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Moderate
Unreviewed
CVE-2025-21267
was published
Feb 7, 2025
Spring Framework has Improperly Implemented Security Check for Standard
Critical
CVE-2018-1275
was published
for
org.springframework:spring-messaging
(Maven)
Oct 17, 2018
Spring Framework allows applications to expose STOMP over WebSocket endpoints
Critical
CVE-2018-1270
was published
for
org.springframework:spring-messaging
(Maven)
Oct 17, 2018
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP...
Critical
Unreviewed
CVE-2016-10229
was published
May 17, 2022
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote...
High
Unreviewed
CVE-2024-6773
was published
Jul 17, 2024
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote...
High
Unreviewed
CVE-2024-6772
was published
Jul 17, 2024
Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote...
High
Unreviewed
CVE-2024-2174
was published
Mar 6, 2024
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote...
Critical
Unreviewed
CVE-2024-3845
was published
Apr 17, 2024
ProTip!
Advisories are also available from the
GraphQL API