GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
12,274 advisories
Filter by severity
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web...
Low
Unreviewed
CVE-2025-52136
was published
Aug 10, 2025
A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic....
Low
Unreviewed
CVE-2025-8774
was published
Aug 9, 2025
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has...
Low
Unreviewed
CVE-2025-8751
was published
Aug 9, 2025
SSRF vulnerability in FreeMarker templates in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay...
Low
Unreviewed
CVE-2025-4655
was published
Aug 9, 2025
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
Low
Unreviewed
CVE-2025-55188
was published
Aug 8, 2025
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low
CVE-2025-54999
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This...
Low
Unreviewed
CVE-2025-8708
was published
Aug 8, 2025
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25...
Low
Unreviewed
CVE-2024-56339
was published
Aug 7, 2025
Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors
Low
GHSA-vh9x-phq6-fx54
was published
for
github.com/rs/cors
(Go)
Aug 6, 2025
•
withdrawn
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive...
Low
Unreviewed
CVE-2025-38746
was published
Aug 6, 2025
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
GHSA-522r-9946-fw43
was published
for
github.com/cloudflare/circl
(Go)
Aug 6, 2025
•
withdrawn
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local...
Low
Unreviewed
CVE-2025-21022
was published
Aug 6, 2025
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local...
Low
Unreviewed
CVE-2025-21023
was published
Aug 6, 2025
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local...
Low
Unreviewed
CVE-2025-21024
was published
Aug 6, 2025
Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Low
CVE-2025-8573
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
RISC Zero Underconstrained Vulnerability: Division
Low
CVE-2025-54873
was published
for
risc0-circuit-rv32im
(Rust)
Aug 5, 2025
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the...
Low
Unreviewed
CVE-2025-44964
was published
Aug 5, 2025
A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects...
Low
Unreviewed
CVE-2025-8534
was published
Aug 5, 2025
The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP...
Low
Unreviewed
CVE-2025-4599
was published
Aug 5, 2025
Exporting a TPM based RSA key larger than 2048 bits from the TPM could overrun a stack buffer if...
Low
Unreviewed
CVE-2025-7844
was published
Aug 5, 2025
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local...
Low
Unreviewed
CVE-2025-46094
was published
Aug 5, 2025
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4....
Low
Unreviewed
CVE-2025-8522
was published
Aug 4, 2025
A vulnerability was found in Intelbras InControl 2.21.60.9 and classified as problematic. This...
Low
Unreviewed
CVE-2025-8515
was published
Aug 4, 2025
ProTip!
Advisories are also available from the
GraphQL API