GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
11,295 advisories
Filter by severity
A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This...
Low
Unreviewed
CVE-2025-7060
was published
Jul 4, 2025
Improper Input Validation vulnerability in Wikimedia Foundation Mediawiki - FeaturedFeeds...
Moderate
Unreviewed
CVE-2025-53502
was published
Jul 3, 2025
A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions...
Moderate
Unreviewed
CVE-2025-6563
was published
Jul 3, 2025
A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol ...
Critical
Unreviewed
CVE-2025-34072
was published
Jul 2, 2025
Lack or insufficent input validation in WebGUI CLI web in Infinera G42
version R6.1.3 allows...
Moderate
Unreviewed
CVE-2025-27023
was published
Jul 2, 2025
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum...
Critical
Unreviewed
CVE-2025-34060
was published
Jul 1, 2025
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi...
Critical
Unreviewed
CVE-2025-34054
was published
Jul 1, 2025
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the...
Critical
Unreviewed
CVE-2025-34056
was published
Jul 1, 2025
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the...
Critical
Unreviewed
CVE-2025-34055
was published
Jul 1, 2025
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This...
Moderate
Unreviewed
CVE-2025-53075
was published
Jun 30, 2025
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers...
Moderate
Unreviewed
CVE-2025-53076
was published
Jun 30, 2025
A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue...
Moderate
Unreviewed
CVE-2025-5878
was published
Jun 29, 2025
A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results...
Moderate
Unreviewed
CVE-2023-28911
was published
Jun 28, 2025
ServiceStack GetErrorResponse Improper Input Validation NTLM Relay Vulnerability. This...
Moderate
Unreviewed
CVE-2025-6444
was published
Jun 26, 2025
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the...
High
Unreviewed
CVE-2025-34031
was published
Jun 26, 2025
A reflected cross-site scripting (XSS) vulnerability exists in the Moodle LMS Jmol plugin version...
Moderate
Unreviewed
CVE-2025-34032
was published
Jun 26, 2025
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and...
Critical
Unreviewed
CVE-2025-34035
was published
Jun 26, 2025
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting...
Critical
Unreviewed
CVE-2025-34036
was published
Jun 26, 2025
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded...
High
Unreviewed
CVE-2025-34033
was published
Jun 26, 2025
An OS command injection vulnerability exists in various models of E-Series Linksys routers via...
Critical
Unreviewed
CVE-2025-34037
was published
Jun 26, 2025
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
Moderate
CVE-2025-52894
was published
for
github.com/openbao/openbao/api/v2
(Go)
Jun 26, 2025
A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1...
Critical
Unreviewed
CVE-2025-34043
was published
Jun 26, 2025
A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing...
High
Unreviewed
CVE-2025-34047
was published
Jun 26, 2025
An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version...
Critical
Unreviewed
CVE-2025-34049
was published
Jun 26, 2025
A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL...
High
Unreviewed
CVE-2025-34048
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API