GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,413
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,656
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
345 advisories
Filter by severity
Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni...
Critical
Unreviewed
CVE-2025-66255
was published
Nov 26, 2025
The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment...
Moderate
Unreviewed
CVE-2025-12752
was published
Nov 22, 2025
eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor...
High
Unreviewed
CVE-2025-34337
was published
Nov 19, 2025
A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function...
Moderate
Unreviewed
CVE-2025-12295
was published
Oct 27, 2025
A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2025-12245
was published
Oct 27, 2025
On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application,...
Moderate
Unreviewed
CVE-2025-12080
was published
Oct 27, 2025
An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows...
Moderate
Unreviewed
CVE-2025-56438
was published
Oct 24, 2025
Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability,...
Low
Unreviewed
CVE-2025-11195
was published
Sep 30, 2025
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to...
Moderate
Unreviewed
CVE-2025-0092
was published
Aug 27, 2025
A vulnerability was determined in Belkin AX1800 1.1.00.016. Affected by this vulnerability is an...
High
Unreviewed
CVE-2025-9379
was published
Aug 24, 2025
A vulnerability was determined in D-Link DIR-619L 6.02CN02. Affected is the function...
Moderate
Unreviewed
CVE-2025-8978
was published
Aug 14, 2025
A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the...
Moderate
Unreviewed
CVE-2025-8979
was published
Aug 14, 2025
A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the...
Moderate
Unreviewed
CVE-2025-8980
was published
Aug 14, 2025
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing...
High
Unreviewed
CVE-2025-6504
was published
Jul 29, 2025
Thunderbird ignored paths when checking the validity of navigations in a frame. This...
Critical
Unreviewed
CVE-2025-8038
was published
Jul 22, 2025
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of...
High
Unreviewed
CVE-2025-30192
was published
Jul 21, 2025
A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41....
Moderate
Unreviewed
CVE-2025-7884
was published
Jul 20, 2025
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162....
High
Unreviewed
CVE-2025-7096
was published
Jul 7, 2025
Pioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity...
Moderate
Unreviewed
CVE-2025-5832
was published
Jun 26, 2025
Pioneer DMH-WT7600NEX Root Filesystem Insufficient Verification of Data Authenticity...
Moderate
Unreviewed
CVE-2025-5833
was published
Jun 26, 2025
The executable file warning did not warn users before opening files with the `terminal` extension...
High
Unreviewed
CVE-2025-6426
was published
Jun 26, 2025
The backup ZIPs are not signed by the application, leading to the possibility that an attacker...
High
Unreviewed
CVE-2025-49199
was published
Jun 12, 2025
IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks...
Critical
Unreviewed
CVE-2025-27558
was published
May 21, 2025
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized...
High
Unreviewed
CVE-2025-29842
was published
May 13, 2025
Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS)...
Moderate
Unreviewed
CVE-2025-27735
was published
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API