GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,124
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
553 advisories
Filter by severity
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable...
Moderate
Unreviewed
CVE-2023-50306
was published
Feb 20, 2024
Umbraco possible user enumeration
Low
CVE-2024-28868
was published
for
UmbracoCMS
(NuGet)
Mar 20, 2024
1Panel's password verification is suspected to have a timing attack vulnerability
Low
CVE-2024-30257
was published
for
github.com/1Panel-dev/1Panel
(Go)
Apr 18, 2024
The login functionality of the web server in affected devices does not normalize the response...
Moderate
Unreviewed
CVE-2023-37482
was published
Feb 11, 2025
Magento Signature verification bypass
High
CVE-2020-9588
was published
for
magento/community-edition
(Composer)
May 24, 2022
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite,...
Moderate
Unreviewed
CVE-2020-35165
was published
May 22, 2024
front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access...
Moderate
Unreviewed
CVE-2022-34125
was published
Apr 16, 2023
SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded...
High
Unreviewed
CVE-2023-29850
was published
Apr 14, 2023
IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar arithmetic
High
CVE-2023-26557
was published
for
github.com/binance-chain/tss-lib
(Go)
Apr 21, 2023
IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar multiplication
Critical
CVE-2023-26556
was published
for
github.com/binance-chain/tss-lib
(Go)
Apr 21, 2023
A specific authentication strategy allows to learn ids of PAM users associated with certain...
Moderate
Unreviewed
CVE-2025-24506
was published
Jan 30, 2025
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to...
Moderate
Unreviewed
CVE-2023-26560
was published
Apr 26, 2023
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in...
High
Unreviewed
CVE-2023-28770
was published
Jul 6, 2023
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through...
Moderate
Unreviewed
CVE-2024-36510
was published
Jan 14, 2025
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition...
Moderate
Unreviewed
CVE-2024-45089
was published
Jan 31, 2025
A validation issue was addressed with improved input sanitization. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2023-28200
was published
May 8, 2023
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13...
Moderate
Unreviewed
CVE-2023-27931
was published
May 8, 2023
Windows MSHTML Platform Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-30040
was published
May 14, 2024
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Critical
Unreviewed
CVE-2025-24146
was published
Jan 28, 2025
IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential...
High
Unreviewed
CVE-2023-27870
was published
May 11, 2023
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web...
High
Unreviewed
CVE-2025-21510
was published
Jan 21, 2025
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an...
Moderate
Unreviewed
CVE-2024-49733
was published
Jan 22, 2025
In multiple locations, there is a possible way to obtain any system permission due to a logic...
High
Unreviewed
CVE-2024-43095
was published
Jan 22, 2025
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to...
High
Unreviewed
CVE-2024-49734
was published
Jan 22, 2025
In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error...
Moderate
Unreviewed
CVE-2024-43763
was published
Jan 22, 2025
ProTip!
Advisories are also available from the
GraphQL API