GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,478
Erlang
33
GitHub Actions
24
Go
2,208
Maven
5,000+
npm
3,865
NuGet
696
pip
3,642
Pub
12
RubyGems
913
Rust
919
Swift
38
Unreviewed advisories
All unreviewed
5,000+
485 advisories
Filter by severity
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic...
High
Unreviewed
CVE-2025-2731
was published
Mar 25, 2025
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic...
High
Unreviewed
CVE-2025-2732
was published
Mar 25, 2025
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and...
High
Unreviewed
CVE-2025-2728
was published
Mar 25, 2025
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic...
High
Unreviewed
CVE-2025-2729
was published
Mar 25, 2025
A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007...
High
Unreviewed
CVE-2025-2727
was published
Mar 25, 2025
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic...
High
Unreviewed
CVE-2025-2730
was published
Mar 25, 2025
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400,...
High
Unreviewed
CVE-2025-2725
was published
Mar 25, 2025
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30...
High
Unreviewed
CVE-2025-2726
was published
Mar 25, 2025
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS...
High
Unreviewed
CVE-2025-25477
was published
Feb 28, 2025
MongoDB Shell may be susceptible to Control Character Injection via autocomplete
High
CVE-2025-1691
was published
for
mongosh
(npm)
Feb 27, 2025
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive...
High
Unreviewed
CVE-2024-12756
was published
Feb 11, 2025
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16...
High
Unreviewed
CVE-2025-0528
was published
Jan 17, 2025
Git LFS permits exfiltration of credentials via crafted HTTP URLs
High
CVE-2024-53263
was published
for
github.com/git-lfs/git-lfs
(Go)
Jan 14, 2025
A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21....
High
Unreviewed
CVE-2025-0396
was published
Jan 12, 2025
SPEmailHandler-PHP has Potential Abuse for Sending Arbitrary Emails
High
CVE-2024-53860
was published
for
spencer14420/sp-php-email-handler
(Composer)
Nov 27, 2024
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All...
High
Unreviewed
CVE-2024-50572
was published
Nov 12, 2024
Plenti arbitrary file deletion vulnerability
High
CVE-2024-49381
was published
for
github.com/plentico/plenti
(Go)
Oct 31, 2024
Plenti arbitrary file write vulnerability
High
CVE-2024-49380
was published
for
github.com/plentico/plenti
(Go)
Oct 31, 2024
SOFA Hessian Remote Command Execution (RCE) Vulnerability
High
CVE-2024-46983
was published
for
com.alipay.sofa:hessian
(Maven)
Sep 19, 2024
Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)
High
CVE-2024-46986
was published
for
camaleon_cms
(RubyGems)
Sep 18, 2024
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to...
High
Unreviewed
CVE-2024-43388
was published
Sep 10, 2024
Withdrawn Advisory: Litestar has an environment Variable injection in `docs-preview.yml` workflow
High
CVE-2024-42370
was published
for
litestar
(pip)
Aug 9, 2024
•
withdrawn
Flowise Path Injection at /api/v1/openai-assistants-file
High
CVE-2024-36420
was published
for
flowise
(npm)
Aug 5, 2024
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable...
High
Unreviewed
CVE-2024-6331
was published
Aug 4, 2024
Dolibarr ERP CRM vulnerable to remote code execution (RCE)
High
CVE-2024-40137
was published
for
dolibarr/dolibarr
(Composer)
Jul 24, 2024
ProTip!
Advisories are also available from the
GraphQL API