GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
45 advisories
Filter by severity
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of...
Moderate
Unreviewed
CVE-2026-44768
was published
Jul 14, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain...
High
Unreviewed
CVE-2026-1784
was published
Jun 2, 2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service...
High
Unreviewed
CVE-2019-25716
was published
Jun 2, 2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1...
High
Unreviewed
CVE-2026-6973
was published
May 7, 2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2026-0232
was published
Apr 13, 2026
Local privilege escalation due to improper handling of environment variables. The following...
High
Unreviewed
CVE-2026-33092
was published
Apr 10, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1,...
Low
Unreviewed
CVE-2026-21422
was published
Mar 4, 2026
The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2025-13091
was published
Feb 19, 2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to...
Moderate
Unreviewed
CVE-2026-0495
was published
Jan 13, 2026
Post-authenticated external control of system web interface configuration setting vulnerability...
Moderate
Unreviewed
CVE-2025-41452
was published
Aug 22, 2025
Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the...
Low
Unreviewed
CVE-2025-27889
was published
Jul 10, 2025
Unauthenticated attackers can send configuration settings to device and possible perform physical...
Moderate
Unreviewed
CVE-2025-30512
was published
Apr 16, 2025
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60...
Moderate
Unreviewed
CVE-2025-27253
was published
Mar 10, 2025
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change...
High
Unreviewed
CVE-2025-0425
was published
Feb 18, 2025
For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker...
High
Unreviewed
CVE-2024-11166
was published
Jan 22, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39800
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39799
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39788
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39793
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39790
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39795
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39798
was published
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API