GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
11,123 advisories
Filter by severity
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS...
Critical
Unreviewed
CVE-2025-30452
was published
Apr 1, 2025
A file access issue was addressed with improved input validation. This issue is fixed in macOS...
High
Unreviewed
CVE-2025-24255
was published
Apr 1, 2025
The issue was addressed with improved validation of environment variables. This issue is fixed in...
Moderate
Unreviewed
CVE-2025-24191
was published
Apr 1, 2025
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport...
High
Unreviewed
CVE-2023-0881
was published
Mar 31, 2025
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7....
Moderate
Unreviewed
CVE-2025-2855
was published
Mar 27, 2025
Synapse vulnerable to federation denial of service via malformed events
High
CVE-2025-30355
was published
for
matrix-synapse
(pip)
Mar 27, 2025
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2025-20227
was published
Mar 27, 2025
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of...
Moderate
Unreviewed
CVE-2025-1440
was published
Mar 26, 2025
The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress...
High
Unreviewed
CVE-2025-1514
was published
Mar 26, 2025
Frappe has Possibility of Remote Code Execution due to improper validation
Moderate
CVE-2025-30213
was published
for
frappe
(pip)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
High
CVE-2025-24514
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
High
CVE-2025-1097
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized mirror annotations
High
CVE-2025-1098
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - auth secret file path traversal vulnerability
Moderate
CVE-2025-24513
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
API Platform Core does not call GraphQl securityAfterResolver
Moderate
CVE-2025-23204
was published
for
api-platform/core
(Composer)
Mar 24, 2025
yiisoft Yii2 Deserialization of Untrusted Data
Moderate
CVE-2025-2689
was published
for
yiisoft/yii2-dev
(Composer)
Mar 24, 2025
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This...
Moderate
Unreviewed
CVE-2025-2690
was published
Mar 24, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
Moderate
Unreviewed
CVE-2024-13666
was published
Mar 22, 2025
Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2025-29814
was published
Mar 21, 2025
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Low
CVE-2025-29923
was published
for
github.com/redis/go-redis/v9
(Go)
Mar 20, 2025
A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection....
Moderate
Unreviewed
CVE-2024-8251
was published
Mar 20, 2025
A vulnerability in ollama/ollama version 0.1.37 allows for remote code execution (RCE) due to...
Critical
Unreviewed
CVE-2024-7773
was published
Mar 20, 2025
A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an...
Moderate
Unreviewed
CVE-2024-12387
was published
Mar 20, 2025
A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This...
High
Unreviewed
CVE-2024-12065
was published
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API