GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,532
Erlang
33
GitHub Actions
25
Go
2,217
Maven
5,000+
npm
3,887
NuGet
700
pip
3,656
Pub
12
RubyGems
913
Rust
933
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,384 advisories
Filter by severity
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the User Interface...
Moderate
Unreviewed
CVE-2025-30654
was published
Apr 9, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure...
Moderate
Unreviewed
CVE-2025-30291
was published
Apr 8, 2025
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an...
High
Unreviewed
CVE-2025-29805
was published
Apr 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency...
Moderate
Unreviewed
CVE-2025-27736
was published
Apr 8, 2025
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access...
Moderate
Unreviewed
CVE-2025-26667
was published
Apr 8, 2025
The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2025-2883
was published
Apr 8, 2025
The GreenPay(tm) by Green.Money plugin for WordPress is vulnerable to Sensitive Information...
Moderate
Unreviewed
CVE-2025-2882
was published
Apr 8, 2025
The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2024-13820
was published
Apr 8, 2025
A vulnerability was found in Vivotek NVR ND8422P, NVR ND9525P and NVR ND9541P 2.4.0.204/3.3.0.104...
Moderate
Unreviewed
CVE-2025-3403
was published
Apr 8, 2025
The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for...
High
Unreviewed
CVE-2024-13604
was published
Apr 7, 2025
There may be information disclosure during memory re-allocation in TZ Secure OS.
Moderate
Unreviewed
CVE-2024-43046
was published
Apr 7, 2025
Path traversal vulnerability in the DFS module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2025-31174
was published
Apr 7, 2025
File read permission bypass vulnerability in the kernel file system module
Impact: Successful...
Moderate
Unreviewed
CVE-2025-31171
was published
Apr 7, 2025
The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2024-11088
was published
Apr 5, 2025
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user...
Low
Unreviewed
CVE-2024-42208
was published
Apr 4, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled...
Moderate
Unreviewed
CVE-2025-2842
was published
Apr 2, 2025
A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and...
Moderate
Unreviewed
CVE-2025-2786
was published
Apr 2, 2025
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via...
Moderate
Unreviewed
CVE-2003-20001
was published
Apr 1, 2025
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This...
Moderate
Unreviewed
CVE-2025-3031
was published
Apr 1, 2025
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13567
was published
Apr 1, 2025
A path handling issue was addressed with improved logic. This issue is fixed in visionOS 2.4,...
Moderate
Unreviewed
CVE-2025-30470
was published
Apr 1, 2025
The issue was addressed with improved restriction of data container access. This issue is fixed...
Critical
Unreviewed
CVE-2025-31183
was published
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API