GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
45 advisories
Filter by severity
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of...
Moderate
Unreviewed
CVE-2026-44768
was published
Jul 14, 2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Moderate
Unreviewed
CVE-2026-0232
was published
Apr 13, 2026
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain...
High
Unreviewed
CVE-2026-1784
was published
Jun 2, 2026
Insufficient configuration management in the listed devices allows authenticated administrators...
Moderate
Unreviewed
CVE-2026-0418
was published
Jun 9, 2026
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1...
High
Unreviewed
CVE-2026-6973
was published
May 7, 2026
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service...
High
Unreviewed
CVE-2019-25716
was published
Jun 2, 2026
An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows...
Moderate
Unreviewed
CVE-2026-30817
was published
Apr 8, 2026
An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0...
Moderate
Unreviewed
CVE-2026-30816
was published
Apr 8, 2026
Local privilege escalation due to improper handling of environment variables. The following...
High
Unreviewed
CVE-2026-33092
was published
Apr 10, 2026
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process...
High
Unreviewed
CVE-2024-1488
was published
Feb 15, 2024
Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1,...
Low
Unreviewed
CVE-2026-21422
was published
Mar 4, 2026
The Shopire theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2025-13091
was published
Feb 19, 2026
SAP Fiori App Intercompany Balance Reconciliation allows an attacker with high privileges to...
Moderate
Unreviewed
CVE-2026-0495
was published
Jan 13, 2026
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39800
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39793
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39799
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39788
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39790
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39795
was published
Jan 14, 2025
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup()...
Critical
Unreviewed
CVE-2024-39798
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality...
Critical
Unreviewed
CVE-2024-39789
was published
Jan 14, 2025
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd...
Critical
Unreviewed
CVE-2024-39794
was published
Jan 14, 2025
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database...
High
Unreviewed
CVE-2024-10979
was published
Nov 14, 2024
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60...
Moderate
Unreviewed
CVE-2025-27253
was published
Mar 10, 2025
Post-authenticated external control of system web interface configuration setting vulnerability...
Moderate
Unreviewed
CVE-2025-41452
was published
Aug 22, 2025
ProTip!
Advisories are also available from the
GraphQL API