GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
16 advisories
Filter by severity
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Moderate
CVE-2026-58428
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker...
Moderate
Unreviewed
CVE-2026-0268
was published
Jun 11, 2026
Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote...
Moderate
Unreviewed
CVE-2026-4913
was published
Apr 14, 2026
AWS API MCP File Access Restriction Bypass
Moderate
CVE-2026-4270
was published
for
awslabs-aws-api-mcp-server
(pip)
Mar 17, 2026
Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9...
Moderate
Unreviewed
CVE-2025-58079
was published
Oct 16, 2025
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a...
Moderate
Unreviewed
CVE-2025-49163
was published
Jun 3, 2025
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a...
Moderate
Unreviewed
CVE-2025-49162
was published
Jun 3, 2025
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript...
Moderate
Unreviewed
CVE-2025-46654
was published
Apr 26, 2025
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG...
Moderate
Unreviewed
CVE-2025-46655
was published
Apr 26, 2025
A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM...
Moderate
Unreviewed
CVE-2025-0113
was published
Feb 12, 2025
An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from...
Moderate
Unreviewed
CVE-2024-8311
was published
Sep 12, 2024
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel,...
Moderate
Unreviewed
CVE-2024-3927
was published
May 22, 2024
A vulnerability in the web-based management interface of Cisco Identity Services Engine could...
Moderate
Unreviewed
CVE-2023-20272
was published
Nov 21, 2023
IBM MQ Appliance 9.3 CD could allow a local attacker to gain elevated privileges on the system,...
Moderate
Unreviewed
CVE-2023-46176
was published
Nov 3, 2023
Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1...
Moderate
Unreviewed
CVE-2022-28782
was published
May 4, 2022
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022...
Moderate
Unreviewed
CVE-2022-24932
was published
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API