GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
11,994 advisories
Filter by severity
parse_string in cJSON before 1.7.18 has a heap-based buffer over-read via {"1":1, with no...
Low
Unreviewed
CVE-2023-53154
was published
May 23, 2025
DNN site Import could use an external source with a crafted request
Low
CVE-2025-48376
was published
for
DotNetNuke.SiteExportImport
(NuGet)
May 23, 2025
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7...
Low
Unreviewed
CVE-2024-9163
was published
May 23, 2025
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript through 10.05.0 lacks...
Low
Unreviewed
CVE-2025-48708
was published
May 23, 2025
TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a...
Low
Unreviewed
CVE-2023-47466
was published
May 22, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In...
Low
Unreviewed
CVE-2025-1110
was published
May 22, 2025
Ackites KillWxapkg Zip Bomb Resource Exhaustion
Low
CVE-2025-5031
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical....
Low
Unreviewed
CVE-2025-5030
was published
May 21, 2025
Missing Authorization vulnerability in Drupal Single Content Sync allows Functionality Misuse...
Low
Unreviewed
CVE-2025-48009
was published
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows XSS
Low
CVE-2025-48206
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized...
Low
Unreviewed
CVE-2025-1420
was published
May 21, 2025
Data provided in a request performed to the server while activating a new device are put in a...
Low
Unreviewed
CVE-2025-1421
was published
May 21, 2025
Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high...
Low
Unreviewed
CVE-2025-1419
was published
May 21, 2025
TYPO3 Unverified Password Change for Backend Users
Low
CVE-2025-47938
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 Allows Information Disclosure via DBAL Restriction Handling
Low
CVE-2025-47937
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
Failed login response could be different depending on whether the username was local or central.
Low
Unreviewed
CVE-2025-48015
was published
May 20, 2025
A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME...
Low
Unreviewed
CVE-2025-4945
was published
May 19, 2025
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3...
Low
Unreviewed
CVE-2025-31185
was published
May 19, 2025
LibreNMS stored Cross-site Scripting vulnerability in poller group name
Low
CVE-2025-47931
was published
for
librenms/librenms
(Composer)
May 19, 2025
a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with...
Low
Unreviewed
CVE-2025-41429
was published
May 19, 2025
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in ...
Low
Unreviewed
CVE-2025-23122
was published
May 19, 2025
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in ...
Low
Unreviewed
CVE-2025-23165
was published
May 19, 2025
O2 UK through 2025-05-17 allows subscribers to determine the Cell ID of other subscribers by...
Low
Unreviewed
CVE-2025-48219
was published
May 18, 2025
A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as...
Low
Unreviewed
CVE-2025-4839
was published
May 18, 2025
ProTip!
Advisories are also available from the
GraphQL API