GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
9,009 advisories
Filter by severity
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line...
Moderate
Unreviewed
CVE-2025-21592
was published
Jan 9, 2025
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid...
High
Unreviewed
CVE-2023-24011
was published
Jan 9, 2025
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid...
High
Unreviewed
CVE-2023-24010
was published
Jan 9, 2025
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid...
High
Unreviewed
CVE-2023-24012
was published
Jan 9, 2025
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12584
was published
Jan 8, 2025
Cross-process screen stack vulnerability in the UIExtension module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-56443
was published
Jan 8, 2025
Cross-process screen stack vulnerability in the UIExtension module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-56435
was published
Jan 8, 2025
Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor...
Moderate
Unreviewed
CVE-2024-12426
was published
Jan 7, 2025
The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in...
Moderate
Unreviewed
CVE-2024-12532
was published
Jan 7, 2025
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2024-11282
was published
Jan 7, 2025
The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress...
Moderate
Unreviewed
CVE-2024-12159
was published
Jan 7, 2025
The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for...
Moderate
Unreviewed
CVE-2024-12140
was published
Jan 7, 2025
The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2024-12538
was published
Jan 7, 2025
The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2024-11290
was published
Jan 7, 2025
fetch: Authorization headers not dropped when redirecting cross-origin
High
CVE-2025-21620
was published
for
deno
(Rust)
Jan 6, 2025
A vulnerability was found in Provision-ISR SH-4050A-2, SH-4100A-2L(MM), SH-8100A-2L(MM), SH...
Moderate
Unreviewed
CVE-2025-0224
was published
Jan 5, 2025
A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup...
Moderate
Unreviewed
CVE-2025-0226
was published
Jan 5, 2025
A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic...
Moderate
Unreviewed
CVE-2025-0227
was published
Jan 5, 2025
A vulnerability classified as problematic has been found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z,...
Moderate
Unreviewed
CVE-2024-13131
was published
Jan 5, 2025
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology...
Moderate
Unreviewed
CVE-2024-13110
was published
Jan 2, 2025
A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802...
Moderate
Unreviewed
CVE-2024-13042
was published
Dec 30, 2024
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
High
Unreviewed
CVE-2024-47922
was published
Dec 30, 2024
Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Moderate
Unreviewed
CVE-2024-47923
was published
Dec 30, 2024
TunnelVision - decloaking VPNs using DHCP
Moderate
GHSA-hqmp-g7ph-x543
was published
for
quincy
(Rust)
Dec 27, 2024
changedetection.io Vulnerable to Improper Input Validation Leading to LFR/Path Traversal
High
CVE-2024-56509
was published
for
changedetection.io
(pip)
Dec 27, 2024
ProTip!
Advisories are also available from the
GraphQL API