GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,965
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
58 advisories
Filter by severity
Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue...
Moderate
Unreviewed
CVE-2024-55548
was published
Dec 10, 2024
Under undisclosed traffic conditions along with conditions beyond the attacker's control,...
High
Unreviewed
CVE-2025-58153
was published
Oct 15, 2025
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022...
High
Unreviewed
CVE-2022-22265
was published
Jan 11, 2022
A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore...
Moderate
Unreviewed
CVE-2025-11594
was published
Oct 11, 2025
In multiple functions of DexUseManagerLocal.java, there is a possible way to crash system server...
Moderate
Unreviewed
CVE-2025-26456
was published
Sep 5, 2025
In Permission Manager, there is a possible way for the microphone privacy indicator to remain...
Low
Unreviewed
CVE-2025-26461
was published
Sep 5, 2025
In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic...
Moderate
Unreviewed
CVE-2025-22413
was published
Aug 27, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6. A...
Moderate
Unreviewed
CVE-2025-43240
was published
Jul 30, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6....
Moderate
Unreviewed
CVE-2025-24188
was published
Jul 30, 2025
The DFX unwind stack module of the ArkCompiler has a vulnerability in interface calling...
High
Unreviewed
CVE-2022-41589
was published
Oct 14, 2022
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple...
Moderate
Unreviewed
CVE-2021-42205
was published
Nov 7, 2022
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests...
Moderate
Unreviewed
CVE-2022-34472
was published
Dec 22, 2022
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It...
High
Unreviewed
CVE-2024-47215
was published
Apr 3, 2025
When run on commands with certain arguments set, explain may fail to validate these arguments...
Moderate
Unreviewed
CVE-2025-3084
was published
Apr 1, 2025
A vulnerability has been found in Dahua products. After
obtaining the administrator's username...
Moderate
Unreviewed
CVE-2024-39945
was published
Jul 31, 2024
The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a...
High
Unreviewed
CVE-2024-50954
was published
Jan 15, 2025
printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does...
Moderate
Unreviewed
CVE-2024-25741
was published
Feb 12, 2024
In updateInputChannel of WindowManagerService.java, there is a possible way to set a touchable...
Moderate
Unreviewed
CVE-2023-21026
was published
Mar 24, 2023
In BitmapExport.java, there is a possible failure to truncate images due to a logic error in the...
Moderate
Unreviewed
CVE-2023-21036
was published
Mar 24, 2023
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-10781
was published
Nov 26, 2024
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could...
High
Unreviewed
CVE-2023-34348
was published
Jan 18, 2024
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
Moderate
Unreviewed
CVE-2024-9104
was published
Oct 16, 2024
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x)...
High
Unreviewed
CVE-2024-22052
was published
Apr 4, 2024
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22...
Moderate
Unreviewed
CVE-2024-22023
was published
Apr 4, 2024
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
22.x) and Ivanti...
High
Unreviewed
CVE-2024-22053
was published
Apr 4, 2024
ProTip!
Advisories are also available from the
GraphQL API