GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,112
Maven
5,000+
npm
3,767
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
264,797 advisories
Filter by severity
Shopware vulnerable to cross-site scripting (XSS)
Moderate
CVE-2022-48150
was published
for
shopware/shopware
(Composer)
Apr 21, 2023
AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending
Moderate
CVE-2023-30610
was published
for
aws-sigv4
(Rust)
Apr 26, 2023
Websites were able to send any requests to the development server and read the response in vite
Moderate
CVE-2025-24010
was published
for
vite
(npm)
Jan 21, 2025
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Moderate
CVE-2024-11741
was published
for
github.com/grafana/grafana
(Go)
Jan 31, 2025
CometBFT allows a malicious peer to make node stuck in blocksync
Moderate
CVE-2025-24371
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Argo CD GitOps Engine does not scrub secret values from patch errors
Moderate
GHSA-274v-mgcv-cm8j
was published
for
github.com/argoproj/gitops-engine
(Go)
Jan 30, 2025
kube-audit-rest's example logging configuration could disclose secret values in the audit log
Moderate
CVE-2025-24884
was published
for
github.com/RichardoC/kube-audit-rest
(Go)
Jan 29, 2025
Go Ethereum vulnerable to DoS via malicious p2p message
Moderate
CVE-2025-24883
was published
for
github.com/ethereum/go-ethereum
(Go)
Jan 30, 2025
Kubewarden-Controller information leak via AdmissionPolicyGroup Resource
Moderate
CVE-2025-24784
was published
for
github.com/kubewarden/kubewarden-controller
(Go)
Jan 30, 2025
KubeWarden's AdmissionPolicy and AdmissionPolicyGroup policies can be used to alter PolicyReport resources
Moderate
CVE-2025-24376
was published
for
github.com/kubewarden/kubewarden-controller
(Go)
Jan 30, 2025
Argo CD does not scrub secret values from patch errors
Moderate
CVE-2025-23216
was published
for
github.com/argoproj/argo-cd
(Go)
Jan 30, 2025
libcurl would wrongly close the same eventfd file descriptor twice when taking
down a connection...
Critical
Unreviewed
CVE-2025-0665
was published
Feb 5, 2025
Memory corruption while configuring a Hypervisor based input virtual device.
High
Unreviewed
CVE-2024-38420
was published
Feb 3, 2025
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow...
Critical
Unreviewed
CVE-2024-50695
was published
Jan 25, 2025
SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow...
Critical
Unreviewed
CVE-2024-50698
was published
Jan 25, 2025
Information disclosure while processing information on firmware image during core initialization.
Moderate
Unreviewed
CVE-2024-38414
was published
Feb 3, 2025
Memory corruption while handling IOCTL call from user-space to set latency level.
High
Unreviewed
CVE-2024-45561
was published
Feb 3, 2025
Information disclosure during audio playback.
Moderate
Unreviewed
CVE-2024-38416
was published
Feb 3, 2025
When libcurl is asked to perform automatic gzip decompression of
content-encoded HTTP responses...
High
Unreviewed
CVE-2025-0725
was published
Feb 5, 2025
In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an...
Critical
Unreviewed
CVE-2024-50694
was published
Jan 25, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-49649
was published
Jan 7, 2025
The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post...
High
Unreviewed
CVE-2024-11601
was published
Nov 22, 2024
The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2024-5646
was published
Jun 11, 2024
The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2024-3559
was published
Jun 12, 2024
ProTip!
Advisories are also available from the
GraphQL API