GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,857
Maven
5,000+
npm
4,488
NuGet
780
pip
4,243
Pub
12
RubyGems
975
Rust
1,095
Swift
49
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147...
Moderate
Unreviewed
CVE-2026-0886
was published
Jan 13, 2026
Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specification
High
CVE-2025-14542
was published
for
utcp
(pip)
Dec 13, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
Moderate
CVE-2025-48938
was published
for
github.com/cli/go-gh/v2
(Go)
May 30, 2025
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode,...
Moderate
Unreviewed
CVE-2025-1118
was published
Feb 19, 2025
Open Cluster Management vulnerable to Trust Boundary Violation
High
CVE-2024-9779
was published
for
open-cluster-management.io/ocm
(Go)
Dec 18, 2024
Visual Studio Code Python Extension Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-49050
was published
Nov 12, 2024
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an...
Moderate
Unreviewed
CVE-2024-20265
was published
Mar 27, 2024
kubevirt-csi: PersistentVolume allows access to HCP's root node
High
CVE-2024-1725
was published
for
github.com/kubevirt/csi-driver
(Go)
Mar 7, 2024
Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
High
GHSA-hj55-9jmv-9jrj
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
•
withdrawn
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which...
High
Unreviewed
CVE-2023-0627
was published
Sep 25, 2023
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If...
High
Unreviewed
CVE-2023-28597
was published
Jul 6, 2023
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are...
Moderate
Unreviewed
CVE-2022-20826
was published
Nov 16, 2022
Class Loading Vulnerability in Artemis
High
CVE-2024-23682
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 9, 2022
Context isolation bypass via contextBridge in Electron
High
CVE-2020-4077
was published
for
electron
(npm)
Jul 7, 2020
Context isolation bypass via leaked cross-context objects in Electron
High
CVE-2020-4076
was published
for
electron
(npm)
Jul 7, 2020
Context isolation bypass via Promise in Electron
Low
CVE-2020-15096
was published
for
electron
(npm)
Jul 7, 2020
ProTip!
Advisories are also available from the
GraphQL API