GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
344 advisories
Filter by severity
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on...
Low
Unreviewed
CVE-2025-11933
was published
Nov 22, 2025
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in...
Low
Unreviewed
CVE-2025-11934
was published
Nov 22, 2025
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is...
Low
Unreviewed
CVE-2025-12889
was published
Nov 22, 2025
Improper input validation in some firmware for some Intel(R) Graphics Drivers and Intel LTS...
Low
Unreviewed
CVE-2025-25216
was published
Nov 11, 2025
A denial-of-service issue was addressed with improved input validation. This issue is fixed in...
Low
Unreviewed
CVE-2025-43365
was published
Nov 4, 2025
Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote...
Low
Unreviewed
CVE-2014-5398
was published
May 17, 2022
HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to...
Low
Unreviewed
CVE-2025-31995
was published
Oct 13, 2025
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability,...
Low
Unreviewed
CVE-2025-11195
was published
Sep 30, 2025
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to...
Low
Unreviewed
CVE-2014-2343
was published
May 17, 2022
A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of...
Low
Unreviewed
CVE-2025-10252
was published
Sep 11, 2025
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import")...
Low
Unreviewed
CVE-2024-5899
was published
Jun 18, 2024
OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a...
Low
Unreviewed
CVE-2025-8662
was published
Sep 3, 2025
Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an...
Low
Unreviewed
CVE-2025-32004
was published
Aug 12, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.
Low
Unreviewed
CVE-2025-25212
was published
Aug 11, 2025
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This...
Low
Unreviewed
CVE-2025-8708
was published
Aug 8, 2025
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a...
Low
Unreviewed
CVE-2025-5992
was published
Jul 11, 2025
A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This...
Low
Unreviewed
CVE-2025-7060
was published
Jul 4, 2025
The issue was addressed with improved validation of environment variables. This issue is fixed in...
Low
Unreviewed
CVE-2023-40394
was published
Jan 11, 2024
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2025-47096
was published
Jun 11, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
Low
Unreviewed
CVE-2025-27242
was published
Jun 8, 2025
Philips SureSigns VS4, A.07.107 and prior. The product receives input or data, but it does not...
Low
Unreviewed
CVE-2020-16237
was published
May 24, 2022
Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna...
Low
Unreviewed
CVE-2025-4762
was published
May 15, 2025
In multiple locations, there is a possible display crash loop due to improper input validation....
Low
Unreviewed
CVE-2022-20543
was published
Dec 19, 2022
Libmenu-cache 1.0.2 insecurely uses /tmp for a socket file, allowing a local user to cause a...
Low
Unreviewed
CVE-2017-8933
was published
May 17, 2022
Insufficient validation of filenames against control characters in Apache Subversion repositories...
Low
Unreviewed
CVE-2024-46901
was published
Dec 9, 2024
ProTip!
Advisories are also available from the
GraphQL API