GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,536
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
81 advisories
Filter by severity
Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows...
Moderate
Unreviewed
CVE-2025-59785
was published
Mar 4, 2026
uv has ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-13327
was published
for
uv
(Rust)
Feb 27, 2026
FacturaScripts has SQL Injection in API ORDER BY Clause
High
CVE-2026-25513
was published
for
facturascripts/facturascripts
(Composer)
Feb 3, 2026
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.
This issue affects BIND...
High
Unreviewed
CVE-2025-13878
was published
Jan 21, 2026
Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an...
Moderate
Unreviewed
CVE-2026-0663
was published
Jan 21, 2026
An Improper Validation of Syntactic Correctness of Input vulnerability in the Web-Filtering...
High
Unreviewed
CVE-2026-21917
was published
Jan 15, 2026
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
Moderate
CVE-2025-67492
was published
for
Weblate
(pip)
Dec 15, 2025
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
High
GHSA-jj37-3377-m6vv
was published
for
nodemailer
(npm)
Nov 14, 2025
•
withdrawn
A low privileged remote attacker can corrupt the webserver users storage on the device by setting...
High
Unreviewed
CVE-2025-41719
was published
Oct 22, 2025
Amazon.IonDotnet is vulnerable to Denial of Service attacks
High
CVE-2025-11573
was published
for
Amazon.IonDotnet
(NuGet)
Oct 9, 2025
IBM Planning Analytics Local 2.0.0 through 2.0.106 and 2.1.0 through 2.1.13
could allow a...
Moderate
Unreviewed
CVE-2025-36262
was published
Sep 30, 2025
github.com/nyaruka/phonenumbers Vulnerable to Improper Validation of Syntactic Correctness of Input
Moderate
CVE-2025-10954
was published
for
github.com/nyaruka/phonenumbers
(Go)
Sep 27, 2025
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an...
Moderate
Unreviewed
CVE-2025-25007
was published
Aug 12, 2025
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
High
CVE-2025-22868
was published
for
golang.org/x/oauth2
(Go)
Jul 18, 2025
An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can...
High
Unreviewed
CVE-2024-51983
was published
Jun 26, 2025
An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language ...
High
Unreviewed
CVE-2024-51982
was published
Jun 26, 2025
Denial of service due to improper handling of malformed input. The following products are...
High
Unreviewed
CVE-2025-30415
was published
Jun 4, 2025
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS...
Moderate
Unreviewed
CVE-2025-24347
was published
Apr 30, 2025
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS...
Moderate
Unreviewed
CVE-2025-24348
was published
Apr 30, 2025
A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote...
High
Unreviewed
CVE-2025-24346
was published
Apr 30, 2025
A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote...
Moderate
Unreviewed
CVE-2025-24345
was published
Apr 30, 2025
Westermo WeOS 5 through 5.23.0 allows a reboot via a malformed ESP packet.
Moderate
Unreviewed
CVE-2025-46419
was published
Apr 24, 2025
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
High
GHSA-3wqc-mwfx-672p
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11...
Moderate
Unreviewed
CVE-2024-52362
was published
Mar 12, 2025
Improper Validation of Syntactic Correctness of Input vulnerability in Finder Fire Safety Finder...
High
Unreviewed
CVE-2024-12146
was published
Mar 6, 2025
ProTip!
Advisories are also available from the
GraphQL API