GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
11,301 advisories
Filter by severity
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user...
Low
Unreviewed
CVE-2024-42174
was published
Jan 11, 2025
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts...
Low
Unreviewed
CVE-2024-42175
was published
Jan 11, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request...
Low
Unreviewed
CVE-2024-13261
was published
Jan 9, 2025
An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the...
Low
Unreviewed
CVE-2025-23113
was published
Jan 11, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request...
Low
Unreviewed
CVE-2024-13293
was published
Jan 9, 2025
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could...
Low
Unreviewed
CVE-2020-9081
was published
Dec 27, 2024
veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
Low
CVE-2024-52800
was published
for
org.verapdf:core
(Maven)
Dec 2, 2024
The Permission Model assumes that any path starting with two backslashes \ has a four-character...
Low
Unreviewed
CVE-2024-37372
was published
Jan 9, 2025
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Low
CVE-2024-55226
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden HTML injection vulnerability
Low
CVE-2024-55224
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Low
CVE-2025-22151
was published
for
strawberry-graphql
(pip)
Jan 9, 2025
JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh
Low
CVE-2025-22149
was published
for
github.com/MicahParks/jwkset
(Go)
Jan 9, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions
Low
CVE-2025-22445
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-22449
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Possible Denial of Service Vulnerability in Rack's header parsing
Low
CVE-2023-27539
was published
for
rack
(RubyGems)
Mar 15, 2023
A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite...
Low
Unreviewed
CVE-2024-10106
was published
Jan 9, 2025
GHSL-2024-288: SickChill open redirect in login
Low
CVE-2024-53995
was published
for
sickchill
(pip)
Jan 8, 2025
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches ...
Low
Unreviewed
CVE-2024-54010
was published
Jan 8, 2025
Under certain circumstances, a user opt-in setting that Focus should require authentication...
Low
Unreviewed
CVE-2025-0245
was published
Jan 7, 2025
In the Linux kernel, the following vulnerability has been resolved:
perf/core: Fix unconditional...
Low
Unreviewed
CVE-2021-46971
was published
Feb 27, 2024
Apache Airflow Fab Provider Insufficient Session Expiration vulnerability
Low
CVE-2024-45033
was published
for
apache-airflow-providers-fab
(pip)
Jan 8, 2025
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0...
Low
Unreviewed
CVE-2024-48455
was published
Jan 7, 2025
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-10562
was published
Jan 7, 2025
ProTip!
Advisories are also available from the
GraphQL API