GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,675
Maven
5,000+
npm
4,297
NuGet
760
pip
4,077
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
25 advisories
Filter by severity
When passing through PCI devices, the detach logic in libxl won't remove
access permissions to...
High
Unreviewed
CVE-2025-58149
was published
Oct 31, 2025
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are...
High
Unreviewed
CVE-2025-55669
was published
Oct 15, 2025
In the Linux kernel, the following vulnerability has been resolved:
io_uring/futex: ensure...
High
Unreviewed
CVE-2025-39698
was published
Sep 5, 2025
Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of...
High
Unreviewed
CVE-2025-6031
was published
Jun 12, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and...
High
Unreviewed
CVE-2025-31253
was published
May 13, 2025
In the Linux kernel, the following vulnerability has been resolved:
dm array: fix releasing a...
High
Unreviewed
CVE-2024-57929
was published
Jan 19, 2025
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7...
High
Unreviewed
CVE-2024-47571
was published
Jan 14, 2025
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause...
High
Unreviewed
CVE-2024-39792
was published
Aug 14, 2024
In the Linux kernel, the following vulnerability has been resolved:
ipc/mqueue, msg, sem: avoid...
High
Unreviewed
CVE-2021-47069
was published
Mar 2, 2024
The caching invalidation guidelines from the AMD-Vi specification (48882—Rev
3.07-PUB—Oct 2022)...
High
Unreviewed
CVE-2023-34326
was published
Jan 5, 2024
By using XSL Transforms, a malicious webserver could have served a user an XSL document that...
High
Unreviewed
CVE-2022-22755
was published
Dec 22, 2022
An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended...
High
Unreviewed
CVE-2022-30256
was published
Nov 19, 2022
A flaw was found in OpenStack. The application credential tokens can be used even after they have...
High
Unreviewed
CVE-2022-2447
was published
Sep 2, 2022
When Responsive Design Mode was enabled, it used references to objects that were previously freed...
High
Unreviewed
CVE-2021-23995
was published
May 24, 2022
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack...
High
Unreviewed
CVE-2020-13530
was published
May 24, 2022
get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege...
High
Unreviewed
CVE-2020-25221
was published
May 24, 2022
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated...
High
Unreviewed
CVE-2020-24030
was published
May 24, 2022
TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to...
High
Unreviewed
CVE-2019-15691
was published
May 24, 2022
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the...
High
Unreviewed
CVE-2017-14895
was published
May 13, 2022
An elevation of privilege vulnerability in CameraBase could enable a local malicious application...
High
Unreviewed
CVE-2017-0544
was published
May 13, 2022
An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol...
High
Unreviewed
CVE-2022-22197
was published
Apr 15, 2022
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its...
High
Unreviewed
CVE-2021-33020
was published
Apr 3, 2022
IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user...
High
Unreviewed
CVE-2022-22332
was published
Apr 2, 2022
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.4),...
High
Unreviewed
CVE-2021-37204
was published
Feb 10, 2022
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.4),...
High
Unreviewed
CVE-2021-37185
was published
Feb 10, 2022
ProTip!
Advisories are also available from the
GraphQL API