GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            113,422 advisories
        Filter by severity
        
      
      
    
                    
                      A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61498
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-63298
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      sqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61141
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Incorrect access control in the Web management interface in Each Italy Wireless Mini Router...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-63422
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-30135
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      HCL DRYiCE AEX product is impacted by Missing
Root Detection vulnerability in the mobile...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-30111
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy),...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61120
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61114
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C.,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61119
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Mobile Scanner Android App version 2.12.38 (package name com.glority.everlens), developed by...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61121
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61196
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12060
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61118
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61117
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61113
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61115
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61116
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
                    
                      
  High
                    
                
                      
                        CVE-2025-64112
                      
                      was published
                        for
                        
                          statamic/cms
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      gnark-crypto allows unchecked memory allocation during vector deserialization
                    
                      
  High
                    
                
                      
                        GHSA-fj2x-735w-74vq
                      
                      was published
                        for
                        
                          github.com/consensys/gnark-crypto
                        
                        (Go)
                      Oct 30, 2025 
                    
                  
                    
                      n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
                    
                      
  High
                    
                
                      
                        CVE-2025-62726
                      
                      was published
                        for
                        
                          n8n
                        
                        (npm)
                      Oct 30, 2025 
                    
                  
                    
                      Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46423
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43940
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43939
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46422
                      
                      was published
                      Oct 30, 2025 
                    
                  
                    
                      Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43941
                      
                      was published
                      Oct 30, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API