GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
12,250 advisories
Filter by severity
Duplicate Advisory: sequoia-openpgp vulnerable to out-of-bounds array access leading to panic
Low
GHSA-rfx3-ffrp-6875
was published
for
sequoia-openpgp
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: buffered-reader vulnerable to out-of-bounds array access leading to panic
Low
GHSA-q5h2-xq96-6gmc
was published
for
buffered-reader
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Unauthenticated Nonce Increment in snow
Low
GHSA-97f8-h76h-f297
was published
for
snow
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: Multiple issues involving quote API in shlex
Low
GHSA-286m-6pg9-v42v
was published
for
shlex
(Rust)
Jul 28, 2025
•
withdrawn
Duplicate Advisory: serde-json-wasm stack overflow during recursive JSON parsing
Low
GHSA-j87p-gjr6-m4pv
was published
for
serde-json-wasm
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: Low severity (DoS) vulnerability in sequoia-openpgp
Low
GHSA-g97w-mw7g-v3jv
was published
for
sequoia-openpgp
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Low
GHSA-4hff-hh47-7788
was published
for
curve25519-dalek
(Rust)
Jul 27, 2025
•
withdrawn
Duplicate Advisory: CosmWasm affected by arithmetic overflows
Low
GHSA-rm83-pxjx-pr5j
was published
for
cosmwasm-std
(Rust)
Jul 27, 2025
•
withdrawn
A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998...
Low
Unreviewed
CVE-2025-8206
was published
Jul 26, 2025
A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179....
Low
Unreviewed
CVE-2025-8204
was published
Jul 26, 2025
JHipster allows privilege escalation via a modified authorities parameter
Low
CVE-2025-43712
was published
for
generator-jhipster
(npm)
Jul 25, 2025
Duplicate Advisory: Koa Open Redirect via Referrer Header (User-Controlled)
Low
GHSA-mvw6-62qv-vmqf
was published
for
koa
(npm)
Jul 25, 2025
•
withdrawn
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated...
Low
Unreviewed
CVE-2025-54568
was published
Jul 25, 2025
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is...
Low
Unreviewed
CVE-2025-0252
was published
Jul 25, 2025
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain...
Low
Unreviewed
CVE-2025-0253
was published
Jul 25, 2025
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple...
Low
Unreviewed
CVE-2025-0251
was published
Jul 25, 2025
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for...
Low
Unreviewed
CVE-2025-0250
was published
Jul 25, 2025
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token...
Low
Unreviewed
CVE-2025-0249
was published
Jul 25, 2025
A potential security vulnerability has been identified in the Poly Clariti Manager for versions...
Low
Unreviewed
CVE-2025-43489
was published
Jul 23, 2025
A potential security vulnerability has been identified in the Poly Clariti Manager for versions...
Low
Unreviewed
CVE-2025-43488
was published
Jul 23, 2025
A vulnerability was found in libssh, where an uninitialized variable exists under certain...
Low
Unreviewed
CVE-2025-4878
was published
Jul 22, 2025
Insertion of sensitive information into log file issue exists in "region PAY" App for Android...
Low
Unreviewed
CVE-2025-52580
was published
Jul 22, 2025
IrfanView CADImage Plugin DWG File Parsing Out-Of-Bounds Read Information Disclosure...
Low
Unreviewed
CVE-2025-7233
was published
Jul 21, 2025
In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated...
Low
Unreviewed
CVE-2025-44657
was published
Jul 21, 2025
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts...
Low
Unreviewed
CVE-2025-54352
was published
Jul 21, 2025
ProTip!
Advisories are also available from the
GraphQL API