GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
104,968 advisories
Filter by severity
Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application...
High
Unreviewed
CVE-2025-12501
was published
Oct 31, 2025
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability...
High
Unreviewed
CVE-2025-57107
was published
Oct 31, 2025
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in...
High
Unreviewed
CVE-2025-57106
was published
Oct 31, 2025
The web server of the device performs exchanges of sensitive information in clear text through an...
High
Unreviewed
CVE-2025-64389
was published
Oct 31, 2025
The
equipment grants a JWT token for each connection in the timeline, but during an
active valid...
High
Unreviewed
CVE-2025-64386
was published
Oct 31, 2025
DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by...
High
Unreviewed
CVE-2025-60749
was published
Oct 31, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-64366
was published
Oct 31, 2025
Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object...
High
Unreviewed
CVE-2025-64353
was published
Oct 31, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-64359
was published
Oct 31, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-64360
was published
Oct 31, 2025
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
High
Unreviewed
CVE-2025-58148
was published
Oct 31, 2025
[This CNA information record relates to multiple CVEs; the
text explains which aspects...
High
Unreviewed
CVE-2025-58147
was published
Oct 31, 2025
When passing through PCI devices, the detach logic in libxl won't remove
access permissions to...
High
Unreviewed
CVE-2025-58149
was published
Oct 31, 2025
Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On...
High
Unreviewed
CVE-2025-11843
was published
Oct 31, 2025
The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price...
High
Unreviewed
CVE-2025-12115
was published
Oct 31, 2025
Malicious or unintentional API requests can be used to add significant amount of data to caches....
High
Unreviewed
CVE-2025-30188
was published
Oct 31, 2025
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key...
High
Unreviewed
CVE-2025-30189
was published
Oct 31, 2025
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords...
High
Unreviewed
CVE-2025-62232
was published
Oct 31, 2025
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due...
High
Unreviewed
CVE-2025-7846
was published
Oct 31, 2025
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all...
High
Unreviewed
CVE-2025-10897
was published
Oct 31, 2025
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command...
High
Unreviewed
CVE-2025-54763
was published
Oct 31, 2025
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if...
High
Unreviewed
CVE-2025-48982
was published
Oct 31, 2025
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in...
High
Unreviewed
CVE-2025-34298
was published
Oct 31, 2025
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which...
High
Unreviewed
CVE-2025-34287
was published
Oct 31, 2025
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated...
High
Unreviewed
CVE-2025-48984
was published
Oct 31, 2025
ProTip!
Advisories are also available from the
GraphQL API