GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
80 advisories
Filter by severity
Under undisclosed traffic conditions along with conditions beyond the attacker's control,...
High
Unreviewed
CVE-2025-58153
was published
Oct 15, 2025
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore...
Moderate
Unreviewed
CVE-2025-11594
was published
Oct 11, 2025
Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
High
CVE-2025-59538
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Sep 30, 2025
Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
High
CVE-2025-59531
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
TinyEnv: Missing .env file not required — may cause unexpected behavior
Moderate
CVE-2025-58758
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server...
Moderate
Unreviewed
CVE-2025-26456
was published
Sep 5, 2025
In Permission Manager, there is a possible way for the microphone privacy indicator to remain...
Low
Unreviewed
CVE-2025-26461
was published
Sep 5, 2025
In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic...
Moderate
Unreviewed
CVE-2025-22413
was published
Aug 27, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. A...
Moderate
Unreviewed
CVE-2025-43240
was published
Jul 30, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6....
Moderate
Unreviewed
CVE-2025-24188
was published
Jul 30, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling...
High
Unreviewed
CVE-2022-41589
was published
Oct 14, 2022
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple...
Moderate
Unreviewed
CVE-2021-42205
was published
Nov 7, 2022
Vyper Does Not Check the Success of Certain Precompile Calls
Low
CVE-2025-21607
was published
for
vyper
(pip)
Jan 14, 2025
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests...
Moderate
Unreviewed
CVE-2022-34472
was published
Dec 22, 2022
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It...
High
Unreviewed
CVE-2024-47215
was published
Apr 3, 2025
When run on commands with certain arguments set, explain may fail to validate these arguments...
Moderate
Unreviewed
CVE-2025-3084
was published
Apr 1, 2025
A vulnerability has been found in Dahua products. After
obtaining the administrator's username...
Moderate
Unreviewed
CVE-2024-39945
was published
Jul 31, 2024
The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a...
High
Unreviewed
CVE-2024-50954
was published
Jan 15, 2025
ntpd NTS client denial of service via wrongly sized cookies
Moderate
GHSA-v83q-83hj-rw38
was published
for
ntpd
(Rust)
Feb 28, 2025
printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does...
Moderate
Unreviewed
CVE-2024-25741
was published
Feb 12, 2024
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable...
Moderate
Unreviewed
CVE-2023-21026
was published
Mar 24, 2023
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the...
Moderate
Unreviewed
CVE-2023-21036
was published
Mar 24, 2023
CometBFT allows a malicious peer to make node stuck in blocksync
Moderate
CVE-2025-24371
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Lodestar snappy decompression issue
Low
GHSA-53rv-hcvm-rpp9
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API