GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      21 advisories
        Filter by severity
        
      
      
    
                    
                      Under undisclosed traffic conditions along with conditions beyond the attacker's control,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58153
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-47215
                      
                      was published
                      Apr 3, 2025 
                    
                  
                    
                      The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-50954
                      
                      was published
                      Jan 15, 2025 
                    
                  
                    
                      The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-10781
                      
                      was published
                      Nov 26, 2024 
                    
                  
                    
                      In wlan, there is a possible denial of service due to incorrect error handling. This could lead...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-20089
                      
                      was published
                      Sep 2, 2024 
                    
                  
                    
                      An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-39514
                      
                      was published
                      Jul 11, 2024 
                    
                  
                    
                      The issue was addressed with improved checks. This issue is fixed in tvOS 17.5, visionOS 1.2, iOS...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-27832
                      
                      was published
                      Jun 10, 2024 
                    
                  
                    
                      An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-29205
                      
                      was published
                      Apr 25, 2024 
                    
                  
                    
                      A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-21894
                      
                      was published
                      Apr 5, 2024 
                    
                  
                    
                      A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
 22.x) and Ivanti...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-22053
                      
                      was published
                      Apr 4, 2024 
                    
                  
                    
                      A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x)...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-22052
                      
                      was published
                      Apr 4, 2024 
                    
                  
                    
                      
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-34348
                      
                      was published
                      Jan 18, 2024 
                    
                  
                    
                      An improper handling of a malformed API request to an API server in Bosch BT software products...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-32230
                      
                      was published
                      Dec 22, 2023 
                    
                  
                    
                      Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-23774
                      
                      was published
                      Aug 29, 2023 
                    
                  
                    
                      An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-36831
                      
                      was published
                      Jul 14, 2023 
                    
                  
                    
                      NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-0204
                      
                      was published
                      Apr 22, 2023 
                    
                  
                    
                      An Improper Check or Handling of Exceptional Conditions within the storm control feature of...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-28965
                      
                      was published
                      Apr 18, 2023 
                    
                  
                    
                      The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-41589
                      
                      was published
                      Oct 14, 2022 
                    
                  
                    
                      Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-25380
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-5031
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-22265
                      
                      was published
                      Jan 11, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API