GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
356 advisories
Filter by severity
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication...
Critical
Unreviewed
CVE-2023-30803
was published
Oct 10, 2023
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18...
Moderate
Unreviewed
CVE-2025-12653
was published
Nov 26, 2025
An attacker could take over a Looker account in a Looker instance configured with OIDC...
Critical
Unreviewed
CVE-2025-12414
was published
Nov 20, 2025
Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and...
Low
Unreviewed
CVE-2025-13015
was published
Nov 11, 2025
Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin...
Critical
Unreviewed
CVE-2025-58595
was published
Nov 6, 2025
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54...
High
Unreviewed
CVE-2025-11209
was published
Nov 7, 2025
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker...
High
Unreviewed
CVE-2025-12430
was published
Nov 10, 2025
An issue was discovered in AnyDesk through 9.0.4. When the connection between two clients is...
High
Unreviewed
CVE-2025-27916
was published
Nov 6, 2025
An inconsistent user interface issue was addressed with improved state management. This issue is...
Moderate
Unreviewed
CVE-2025-43503
was published
Nov 4, 2025
The issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1,...
Moderate
Unreviewed
CVE-2025-43493
was published
Nov 4, 2025
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a...
Moderate
Unreviewed
CVE-2024-34397
was published
May 7, 2024
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking...
Moderate
Unreviewed
CVE-2023-51323
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software...
Moderate
Unreviewed
CVE-2023-51327
was published
Feb 20, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS...
Moderate
Unreviewed
CVE-2023-42889
was published
Feb 21, 2024
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software...
Moderate
Unreviewed
CVE-2023-51326
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Night Club Booking...
Moderate
Unreviewed
CVE-2023-51321
was published
Feb 20, 2025
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27861
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations...
Moderate
Unreviewed
CVE-2021-27854
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27862
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed...
Moderate
Unreviewed
CVE-2021-27853
was published
Sep 28, 2022
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check...
Moderate
Unreviewed
CVE-2020-25686
was published
May 24, 2022
This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17...
Moderate
Unreviewed
CVE-2023-41069
was published
Jan 11, 2024
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This...
High
Unreviewed
CVE-2024-10462
was published
Oct 29, 2024
An attacker could cause a select dropdown to be shown over another tab; this could have led to...
Moderate
Unreviewed
CVE-2024-11692
was published
Nov 26, 2024
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This...
High
Unreviewed
CVE-2024-10465
was published
Oct 29, 2024
ProTip!
Advisories are also available from the
GraphQL API