GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
71 advisories
Filter by severity
MTProto proxy remote code execution vulnerability
High
CVE-2023-45312
was published
for
mtproto_proxy
(Erlang)
Oct 10, 2023
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther...
High
Unreviewed
CVE-2023-27516
was published
Oct 12, 2023
Initialization of a resource with an insecure default vulnerability in OET-213H-BTS1 sold in...
High
Unreviewed
CVE-2024-25972
was published
Mar 1, 2024
Apache ActiveMQ's default configuration doesn't secure the API web context
High
CVE-2024-32114
was published
for
org.apache.activemq:apache-activemq
(Maven)
May 2, 2024
Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver...
High
Unreviewed
CVE-2024-41995
was published
Aug 6, 2024
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the...
High
Unreviewed
CVE-2024-6788
was published
Aug 13, 2024
In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to...
High
Unreviewed
CVE-2024-34734
was published
Aug 16, 2024
Firefox normally asks for confirmation before asking the operating system to find an application...
High
Unreviewed
CVE-2024-8383
was published
Sep 3, 2024
Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote...
High
Unreviewed
CVE-2024-47295
was published
Oct 1, 2024
Insecure Default Initialization of Resource vulnerability in Apache Solr
High
CVE-2024-45217
was published
for
org.apache.solr:solr
(Maven)
Oct 16, 2024
Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with...
High
Unreviewed
CVE-2019-25219
was published
Oct 29, 2024
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
High
Unreviewed
CVE-2025-43015
was published
Apr 17, 2025
A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All...
High
Unreviewed
CVE-2025-31930
was published
May 13, 2025
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure...
High
Unreviewed
CVE-2025-25271
was published
Jul 8, 2025
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk...
High
Unreviewed
CVE-2025-44647
was published
Jul 21, 2025
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for...
High
Unreviewed
CVE-2025-36222
was published
Sep 11, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a...
High
Unreviewed
CVE-2025-48621
was published
Dec 8, 2025
In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become...
High
Unreviewed
CVE-2025-48629
was published
Dec 8, 2025
ProTip!
Advisories are also available from the
GraphQL API