GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
11,322 advisories
Filter by severity
Vaultwarden HTML injection vulnerability
Low
CVE-2024-55224
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request...
Low
Unreviewed
CVE-2024-13293
was published
Jan 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request...
Low
Unreviewed
CVE-2024-13261
was published
Jan 9, 2025
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Low
CVE-2025-22151
was published
for
strawberry-graphql
(pip)
Jan 9, 2025
JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh
Low
CVE-2025-22149
was published
for
github.com/MicahParks/jwkset
(Go)
Jan 9, 2025
A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite...
Low
Unreviewed
CVE-2024-10106
was published
Jan 9, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions
Low
CVE-2025-22445
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-22449
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
The Permission Model assumes that any path starting with two backslashes \ has a four-character...
Low
Unreviewed
CVE-2024-37372
was published
Jan 9, 2025
GHSL-2024-288: SickChill open redirect in login
Low
CVE-2024-53995
was published
for
sickchill
(pip)
Jan 8, 2025
A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches ...
Low
Unreviewed
CVE-2024-54010
was published
Jan 8, 2025
Apache Airflow Fab Provider Insufficient Session Expiration vulnerability
Low
CVE-2024-45033
was published
for
apache-airflow-providers-fab
(pip)
Jan 8, 2025
Under certain circumstances, a user opt-in setting that Focus should require authentication...
Low
Unreviewed
CVE-2025-0245
was published
Jan 7, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote...
Low
Unreviewed
CVE-2021-20455
was published
Jan 7, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Low
Unreviewed
CVE-2024-12425
was published
Jan 7, 2025
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2024-10562
was published
Jan 7, 2025
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not...
Low
Unreviewed
CVE-2024-10102
was published
Jan 7, 2025
The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
Low
Unreviewed
CVE-2024-10527
was published
Jan 7, 2025
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0...
Low
Unreviewed
CVE-2024-48455
was published
Jan 7, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0...
Low
Unreviewed
CVE-2024-51472
was published
Jan 6, 2025
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')...
Low
Unreviewed
CVE-2024-12970
was published
Jan 6, 2025
A vulnerability was found in TMD Custom Header Menu 4.0.0.1 on OpenCart. It has been rated as...
Low
Unreviewed
CVE-2025-0214
was published
Jan 4, 2025
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage....
Low
Unreviewed
CVE-2024-55541
was published
Jan 2, 2025
ProTip!
Advisories are also available from the
GraphQL API