GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
95 advisories
Filter by severity
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before...
Moderate
Unreviewed
CVE-2025-4979
was published
May 22, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17...
Moderate
Unreviewed
CVE-2025-1278
was published
May 9, 2025
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1,...
Moderate
Unreviewed
CVE-2025-31201
was published
Apr 16, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 13.12 before 17.8.7, 17...
Moderate
Unreviewed
CVE-2025-2408
was published
Apr 10, 2025
Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.
High
Unreviewed
CVE-2024-33058
was published
Apr 7, 2025
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0...
High
Unreviewed
CVE-2025-29987
was published
Apr 3, 2025
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9...
Moderate
Unreviewed
CVE-2024-12619
was published
Mar 28, 2025
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and...
High
Unreviewed
CVE-2025-20111
was published
Feb 26, 2025
The product implements access controls via a policy or other feature with the intention to...
Moderate
Unreviewed
CVE-2024-6696
was published
Feb 20, 2025
Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow...
Moderate
Unreviewed
CVE-2024-39279
was published
Feb 13, 2025
Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows®...
Moderate
Unreviewed
CVE-2024-21971
was published
Feb 12, 2025
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM,...
High
Unreviewed
CVE-2023-31343
was published
Feb 12, 2025
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM,...
High
Unreviewed
CVE-2023-31342
was published
Feb 12, 2025
Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper...
High
Unreviewed
CVE-2024-53295
was published
Feb 1, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to...
Moderate
Unreviewed
CVE-2024-11931
was published
Jan 24, 2025
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows...
Moderate
Unreviewed
CVE-2024-13272
was published
Jan 9, 2025
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful...
High
Unreviewed
CVE-2024-13256
was published
Jan 9, 2025
Outlook for Android Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2024-43604
was published
Oct 8, 2024
Withdrawn Advisory: Lunary information disclosure vulnerability
Moderate
CVE-2024-6867
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
Low
CVE-2024-39324
was published
for
aimeos/ai-admin-graphql
(Composer)
Jul 2, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
High
CVE-2024-39323
was published
for
aimeos/ai-admin-graphql
(Composer)
Jul 2, 2024
lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management
Moderate
CVE-2024-5389
was published
for
lunary
(npm)
Jun 10, 2024
•
withdrawn
Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an...
High
Unreviewed
CVE-2023-45217
was published
May 16, 2024
ProTip!
Advisories are also available from the
GraphQL API