GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,796
Maven
5,000+
npm
4,410
NuGet
772
pip
4,181
Pub
12
RubyGems
965
Rust
1,078
Swift
45
Unreviewed advisories
All unreviewed
5,000+
185 advisories
Filter by severity
Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin...
Critical
Unreviewed
CVE-2025-56332
was published
Dec 30, 2025
Incorrect configuration of replication security in the MariaDB component of the infra-operator in...
Moderate
Unreviewed
CVE-2025-14758
was published
Dec 16, 2025
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
Moderate
CVE-2025-66482
was published
for
misskey-js
(npm)
Dec 15, 2025
In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and...
Moderate
Unreviewed
CVE-2025-64781
was published
Dec 12, 2025
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a...
High
Unreviewed
CVE-2025-48621
was published
Dec 8, 2025
In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become...
High
Unreviewed
CVE-2025-48629
was published
Dec 8, 2025
The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers...
Moderate
Unreviewed
CVE-2025-52622
was published
Dec 2, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Ray's New Token Authentication is Disabled By Default
Critical
CVE-2025-34351
was published
for
ray
(pip)
Nov 27, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
The default configuration of WatchGuard Firebox devices through 2025-09-10 allows administrative...
Critical
Unreviewed
CVE-2025-59396
was published
Nov 6, 2025
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker...
Moderate
Unreviewed
CVE-2025-35021
was published
Nov 4, 2025
Jenkins Eggplant Runner Plugin protection mechanism disabled
Moderate
CVE-2025-64135
was published
for
io.jenkins.plugins:eggplant-runner
(Maven)
Oct 29, 2025
In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Fix...
Moderate
Unreviewed
CVE-2022-49099
was published
Oct 14, 2025
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with...
Moderate
Unreviewed
CVE-2025-41245
was published
Sep 29, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
During a short time frame while the device is booting an unauthenticated remote attacker can send...
Moderate
Unreviewed
CVE-2025-41713
was published
Sep 15, 2025
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for...
High
Unreviewed
CVE-2025-36222
was published
Sep 11, 2025
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept...
Moderate
Unreviewed
CVE-2025-32330
was published
Sep 4, 2025
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix the smbd_response...
Moderate
Unreviewed
CVE-2025-38523
was published
Aug 16, 2025
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation...
Critical
Unreviewed
CVE-2025-7353
was published
Aug 14, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk...
High
Unreviewed
CVE-2025-44647
was published
Jul 21, 2025
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure...
High
Unreviewed
CVE-2025-25271
was published
Jul 8, 2025
ProTip!
Advisories are also available from the
GraphQL API