GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,764 advisories
Filter by severity
An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve...
Moderate
Unreviewed
CVE-2025-32098
was published
Sep 5, 2025
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
In AccessibilityServiceConnection.java, there is a possible background activity launch due to a...
High
Unreviewed
CVE-2025-26462
was published
Sep 5, 2025
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a...
High
Unreviewed
CVE-2025-26435
was published
Sep 5, 2025
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a...
High
Unreviewed
CVE-2025-32345
was published
Sep 4, 2025
frost-core: refresh shares with smaller min_signers will reduce security of group
Moderate
CVE-2025-58359
was published
for
frost-core
(Rust)
Sep 3, 2025
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the...
High
Unreviewed
CVE-2024-46916
was published
Aug 29, 2025
Contao does not properly manage privileges for page and article fields
Moderate
CVE-2025-57759
was published
for
contao/contao
(Composer)
Aug 28, 2025
D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch...
High
Unreviewed
CVE-2025-55582
was published
Aug 27, 2025
A non-primary administrator user with admin rights to the web interface but without shell access...
High
Unreviewed
CVE-2025-36729
was published
Aug 26, 2025
The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to,...
High
Unreviewed
CVE-2025-6366
was published
Aug 26, 2025
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in...
High
Unreviewed
CVE-2025-5931
was published
Aug 26, 2025
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
High
CVE-2025-57760
was published
for
langflow
(pip)
Aug 25, 2025
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure...
High
Unreviewed
CVE-2025-55581
was published
Aug 22, 2025
Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime ...
Moderate
Unreviewed
CVE-2025-55627
was published
Aug 22, 2025
There is an improper privilege management vulnerability identified in ManageEngine's Asset...
High
Unreviewed
CVE-2025-8309
was published
Aug 20, 2025
The StrongDM Windows service incorrectly handled communication related to system certificate...
High
Unreviewed
CVE-2025-6182
was published
Aug 20, 2025
CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation...
High
Unreviewed
CVE-2025-8453
was published
Aug 20, 2025
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-6758
was published
Aug 19, 2025
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-8218
was published
Aug 19, 2025
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized...
High
Unreviewed
CVE-2025-6080
was published
Aug 16, 2025
ProTip!
Advisories are also available from the
GraphQL API