GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,811
Erlang
36
GitHub Actions
32
Go
2,396
Maven
5,000+
npm
4,033
NuGet
721
pip
3,824
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
402 advisories
Filter by severity
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1...
High
Unreviewed
CVE-2025-8181
was published
Jul 26, 2025
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can elevate to...
Moderate
Unreviewed
CVE-2025-31513
was published
Jul 22, 2025
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-7947
was published
Jul 22, 2025
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in...
Critical
Unreviewed
CVE-2025-44655
was published
Jul 21, 2025
Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce...
Critical
Unreviewed
CVE-2025-52836
was published
Jul 16, 2025
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16 and...
Moderate
Unreviewed
CVE-2025-7576
was published
Jul 14, 2025
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-7552
was published
Jul 14, 2025
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital...
Moderate
Unreviewed
CVE-2025-0139
was published
Jul 10, 2025
An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on...
Moderate
Unreviewed
CVE-2025-0140
was published
Jul 10, 2025
The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can...
Moderate
Unreviewed
CVE-2025-27028
was published
Jul 9, 2025
Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation...
High
Unreviewed
CVE-2025-47422
was published
Jul 8, 2025
SAPCAR allows an attacker logged in with high privileges to override the permissions of the...
Moderate
Unreviewed
CVE-2025-43001
was published
Jul 8, 2025
SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in...
Moderate
Unreviewed
CVE-2025-42992
was published
Jul 8, 2025
A vulnerability was found in BlackVue Dashcam 590X up to 20250624. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-7076
was published
Jul 6, 2025
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege...
Critical
Unreviewed
CVE-2025-49867
was published
Jul 4, 2025
Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking allows Privilege...
Critical
Unreviewed
CVE-2025-23970
was published
Jul 4, 2025
The misconfiguration in the sudoers configuration of the operating system in
Infinera G42...
High
Unreviewed
CVE-2025-27021
was published
Jul 2, 2025
Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb...
Critical
Unreviewed
CVE-2025-45006
was published
Jul 1, 2025
A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60...
Moderate
Unreviewed
CVE-2025-6765
was published
Jun 27, 2025
Incorrect Privilege Assignment vulnerability in pebas CouponXxL Custom Post Types allows...
High
Unreviewed
CVE-2025-52726
was published
Jun 27, 2025
JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing Import Page component
Low
CVE-2025-6735
was published
for
juzaweb/cms
(Composer)
Jun 27, 2025
JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing certain components
Low
CVE-2025-6736
was published
for
juzaweb/cms
(Composer)
Jun 27, 2025
Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates ...
High
Unreviewed
CVE-2025-41255
was published
Jun 26, 2025
NVIDIA AIStore contains a vulnerability in the AIS Operator where a user may gain elevated k8s...
Moderate
Unreviewed
CVE-2025-23260
was published
Jun 26, 2025
A vulnerability classified as problematic was found in NOYAFA/Xiami LF9 Pro up to 20250611....
Moderate
Unreviewed
CVE-2025-6532
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API