GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
75 advisories
Filter by severity
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Critical
CVE-2026-73843
was published
for
github.com/openchoreo/openchoreo
(Go)
Sep 2, 2026
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct...
Critical
Unreviewed
CVE-2021-42640
was published
Feb 9, 2022
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author...
Critical
Unreviewed
CVE-2026-42535
was published
Jun 8, 2026
vm2 Has a Sandbox Breakout Using Async Generator
Critical
CVE-2026-45411
was published
for
vm2
(npm)
May 14, 2026
vm2 has Sandbox Breakout Through Null Proto Exception
Critical
CVE-2026-44009
was published
for
vm2
(npm)
May 8, 2026
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
Critical
CVE-2026-44008
was published
for
vm2
(npm)
May 8, 2026
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an...
Critical
Unreviewed
CVE-2026-20160
was published
Apr 1, 2026
An issue in Fronius Datalogger Web v.2.0.5-4, allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2023-37621
was published
Feb 1, 2024
Workers for local Dask clusters mistakenly listened on public interfaces
Critical
CVE-2021-42343
was published
for
distributed
(pip)
Jul 15, 2022
Duplicate Advisory: Remote code execution in dask
Critical
GHSA-j8fq-86c5-5v2r
was published
for
dask
(pip)
Oct 27, 2021
•
withdrawn
Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from...
Critical
Unreviewed
CVE-2025-25176
was published
Jan 13, 2026
Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that...
Critical
Unreviewed
CVE-2025-15114
was published
Dec 31, 2025
Following the sandbox escape in CVE-2025-2783, various Firefox developers identified a similar...
Critical
Unreviewed
CVE-2025-2857
was published
Mar 27, 2025
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product...
Critical
Unreviewed
CVE-2021-35211
was published
May 24, 2022
A vulnerability was identified in Docker Desktop that allows local running Linux containers to...
Critical
Unreviewed
CVE-2025-9074
was published
Aug 20, 2025
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows...
Critical
Unreviewed
CVE-2024-25153
was published
Mar 13, 2024
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator...
Critical
Unreviewed
CVE-2022-25236
was published
Feb 17, 2022
TigerVNC accessible via the network and not just via a UNIX socket as intended
Critical
CVE-2025-32428
was published
for
jupyter-remote-desktop-proxy
(pip)
Apr 12, 2025
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400...
Critical
Unreviewed
CVE-2022-4390
was published
Dec 9, 2022
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS)...
Critical
Unreviewed
CVE-2022-48198
was published
Jan 1, 2023
An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers...
Critical
Unreviewed
CVE-2023-45911
was published
Oct 18, 2023
Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on A77, A78, A78C,...
Critical
Unreviewed
CVE-2024-5660
was published
Dec 10, 2024
python-docutils allows insecure usage of temporary files
Critical
CVE-2009-5042
was published
for
docutils
(pip)
Mar 13, 2020
Exposure of Resource to Wrong Sphere in Apache Tomcat
Critical
CVE-2017-5648
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 13, 2022
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (...
Critical
Unreviewed
CVE-2022-32221
was published
Dec 6, 2022
ProTip!
Advisories are also available from the
GraphQL API