GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,047 advisories
Filter by severity
Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is...
Low
Unreviewed
CVE-2025-51643
was published
Aug 28, 2025
A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an...
Low
Unreviewed
CVE-2025-9381
was published
Aug 24, 2025
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that...
Low
Unreviewed
CVE-2025-8448
was published
Aug 20, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Low
Unreviewed
CVE-2025-27707
was published
Aug 12, 2025
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive...
Low
Unreviewed
CVE-2025-38746
was published
Aug 6, 2025
A vulnerability was found in Intelbras InControl 2.21.60.9 and classified as problematic. This...
Low
Unreviewed
CVE-2025-8515
was published
Aug 4, 2025
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a guest could get...
Low
Unreviewed
CVE-2025-23290
was published
Aug 3, 2025
HCL Connections is vulnerable to an information disclosure vulnerability that could allow a user...
Low
Unreviewed
CVE-2024-42209
was published
Jul 17, 2025
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform...
Low
Unreviewed
CVE-2025-20325
was published
Jul 7, 2025
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is...
Low
Unreviewed
CVE-2025-6199
was published
Jun 17, 2025
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software...
Low
Unreviewed
CVE-2025-20030
was published
May 13, 2025
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Low
CVE-2025-46720
was published
for
@keystone-6/core
(npm)
May 5, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-32698
was published
Apr 10, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-32700
was published
Apr 10, 2025
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user...
Low
Unreviewed
CVE-2024-42208
was published
Apr 4, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
This issue was addressed by restricting options offered on a locked device. This issue is fixed...
Low
Unreviewed
CVE-2024-44179
was published
Mar 10, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
CVE-2025-27221
was published
for
uri
(RubyGems)
Mar 3, 2025
HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user...
Low
Unreviewed
CVE-2024-23563
was published
Feb 12, 2025
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0...
Low
Unreviewed
CVE-2024-52966
was published
Feb 11, 2025
In affected versions of Octopus Server the preview import feature could be leveraged to identify...
Low
Unreviewed
CVE-2025-0525
was published
Feb 11, 2025
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Low
Unreviewed
CVE-2024-54475
was published
Jan 28, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-23073
was published
Jan 14, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-23074
was published
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API