GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,714
Maven
5,000+
npm
5,000+
NuGet
1,110
pip
5,000+
Pub
13
RubyGems
1,151
Rust
1,567
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
137 advisories
Filter by severity
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an...
Moderate
Unreviewed
CVE-2025-59259
was published
Oct 14, 2025
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker...
High
Unreviewed
CVE-2025-55701
was published
Oct 14, 2025
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an...
Moderate
Unreviewed
CVE-2025-58729
was published
Oct 14, 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This...
High
Unreviewed
CVE-2025-20711
was published
Oct 14, 2025
Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured...
Low
Unreviewed
CVE-2025-58084
was published
Oct 13, 2025
Synapse's invalid device keys degrade federation functionality
Moderate
CVE-2025-61672
was published
for
matrix-synapse
(pip)
Oct 8, 2025
A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker...
High
Unreviewed
CVE-2025-20327
was published
Sep 24, 2025
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects...
High
Unreviewed
CVE-2025-10207
was published
Sep 18, 2025
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code...
High
Unreviewed
CVE-2024-48851
was published
Sep 18, 2025
Due to missing input validation, an attacker with high privilege access to ABAP reports could...
High
Unreviewed
CVE-2025-42929
was published
Sep 9, 2025
Due to missing input validation, an attacker with high privilege access to ABAP reports could...
High
Unreviewed
CVE-2025-42916
was published
Sep 9, 2025
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security...
High
Unreviewed
CVE-2025-20244
was published
Aug 14, 2025
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security...
High
Unreviewed
CVE-2025-20251
was published
Aug 14, 2025
A security issue exists due to improper handling of CIP Class 32’s request when a module is...
High
Unreviewed
CVE-2025-9042
was published
Aug 14, 2025
A security issue exists due to improper handling of CIP Class 32’s request when a module is...
High
Unreviewed
CVE-2025-9041
was published
Aug 14, 2025
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary...
Moderate
Unreviewed
CVE-2025-30027
was published
Aug 12, 2025
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
High
CVE-2025-54525
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2...
Moderate
Unreviewed
CVE-2024-40682
was published
Jul 23, 2025
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message...
Low
Unreviewed
CVE-2025-24335
was published
Jul 2, 2025
Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR...
Moderate
Unreviewed
CVE-2025-40910
was published
Jun 27, 2025
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2025-25020
was published
Jun 3, 2025
Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero...
Moderate
Unreviewed
CVE-2025-40911
was published
May 28, 2025
An unauthenticated remote attacker can exploit input validation in cmd services of the devices,...
High
Unreviewed
CVE-2025-41650
was published
May 27, 2025
A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2025-20155
was published
May 7, 2025
ProTip!
Advisories are also available from the
GraphQL API