GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
24 advisories
Filter by severity
Context isolation bypass in Electron
Low
CVE-2020-15215
was published
for
electron
(npm)
Oct 6, 2020
A user without PR can reset user authentication failures information
Low
CVE-2021-32729
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-script
(Maven)
Jul 2, 2021
Agent-to-controller security bypass in Jenkins HashiCorp Vault Plugin
Low
CVE-2022-25186
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
Feb 16, 2022
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3...
Low
Unreviewed
CVE-2019-13535
was published
May 24, 2022
In various functions of ap_input_processor.c, there is a possible way to record audio during a...
Low
Unreviewed
CVE-2022-20562
was published
Dec 21, 2022
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on...
Low
Unreviewed
CVE-2023-5875
was published
Nov 2, 2023
A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as...
Low
Unreviewed
CVE-2023-4466
was published
Dec 29, 2023
A privileged attacker
can prevent delivery of debug exceptions to SEV-SNP guests potentially...
Low
Unreviewed
CVE-2023-20573
was published
Jan 11, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-20923
was published
Feb 17, 2024
Mattermost Desktop App allows for bypassing TCC restrictions on macOS
Low
CVE-2024-36287
was published
for
mattermost-desktop
(npm)
Jun 14, 2024
Mattermost Desktop App fails to sufficiently configure Electron Fuses
Low
CVE-2024-45835
was published
for
mattermost-desktop
(npm)
Sep 16, 2024
Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may...
Low
Unreviewed
CVE-2024-38660
was published
Nov 13, 2024
A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as...
Low
Unreviewed
CVE-2025-0575
was published
Jan 20, 2025
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
Protection mechanism failure for some Edge Orchestrator software for Intel(R) Tiber™ Edge...
Low
Unreviewed
CVE-2025-21081
was published
May 13, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
Low
GHSA-phhq-63jg-fp7r
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 9, 2025
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to...
Low
Unreviewed
CVE-2025-52615
was published
Oct 12, 2025
Protobuf Maven Plugin protocDigest is ignored when using protoc from PATH
Low
GHSA-j2pc-v64r-mv4f
was published
for
io.github.ascopes:protobuf-maven-plugin
(Maven)
Nov 4, 2025
Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing
Low
CVE-2025-66479
was published
for
@anthropic-ai/sandbox-runtime
(npm)
Dec 4, 2025
Envoy forwards early CONNECT data in TCP proxy mode
Low
CVE-2025-64763
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost...
Low
Unreviewed
CVE-2025-13326
was published
Dec 17, 2025
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of...
Low
Unreviewed
CVE-2025-55249
was published
Jan 19, 2026
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
Low
GHSA-8mf7-vv8w-hjr2
was published
for
openclaw
(npm)
Mar 3, 2026
@whyour/qinglong: manipulation of the argument command leads to protection mechanism failure
Low
CVE-2026-3965
was published
for
@whyour/qinglong
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API