GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
24 advisories
Filter by severity
Crafter CMS has Improper Control of Dynamically-Managed Code Resources
Moderate
CVE-2026-1770
was published
for
org.craftercms:craftercms
(Maven)
Feb 2, 2026
A vulnerability was determined in SamuNatsu HaloBot up to...
Moderate
Unreviewed
CVE-2025-14695
was published
Dec 15, 2025
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2025-14085
was published
Dec 5, 2025
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById...
Moderate
Unreviewed
CVE-2025-14051
was published
Dec 5, 2025
Improper control of dynamically-managed code resources vulnerability in WebAPI component in...
Moderate
Unreviewed
CVE-2024-5401
was published
Dec 4, 2025
Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring...
Moderate
Unreviewed
CVE-2025-26405
was published
Nov 11, 2025
Rack has a Possible Information Disclosure Vulnerability
Moderate
CVE-2025-61780
was published
for
rack
(RubyGems)
Oct 10, 2025
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use,...
Moderate
Unreviewed
CVE-2025-46673
was published
Apr 27, 2025
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Moderate
CVE-2025-31674
was published
for
drupal/core
(Composer)
Apr 1, 2025
Sentry SDK Prototype Pollution gadget in JavaScript SDKs
Moderate
GHSA-593m-55hh-j8gv
was published
for
@sentry/browser
(npm)
Oct 3, 2024
Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on...
Moderate
Unreviewed
CVE-2024-2537
was published
Mar 15, 2024
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross...
Moderate
Unreviewed
CVE-2023-6184
was published
Jan 18, 2024
Eclipse Glassfish remote code execution issue
Moderate
CVE-2023-5763
was published
for
org.glassfish.main.orb:orb-connector
(Maven)
Nov 3, 2023
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the...
Moderate
Unreviewed
CVE-2023-39983
was published
Sep 2, 2023
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
Moderate
CVE-2022-4318
was published
for
github.com/cri-o/cri-o
(Go)
Dec 29, 2022
Budibase Improper Access Control vulnerability
Moderate
CVE-2022-3225
was published
for
@budibase/bbui
(npm)
Sep 17, 2022
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2...
Moderate
Unreviewed
CVE-2020-15372
was published
May 24, 2022
An information disclosure vulnerability exists when the Windows GDI component improperly...
Moderate
Unreviewed
CVE-2020-1097
was published
May 24, 2022
An information disclosure vulnerability exists when the Windows GDI component improperly...
Moderate
Unreviewed
CVE-2020-1091
was published
May 24, 2022
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in...
Moderate
Unreviewed
CVE-2019-15006
was published
May 24, 2022
GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values...
Moderate
Unreviewed
CVE-2012-2055
was published
May 17, 2022
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS...
Moderate
Unreviewed
CVE-2019-1595
was published
May 13, 2022
Header dropping in traefik
Moderate
CVE-2021-32813
was published
for
github.com/traefik/traefik
(Go)
Aug 5, 2021
Improper Control of Dynamically-Managed Code Resources in config-shield
Moderate
CVE-2021-26276
was published
for
config-shield
(npm)
Apr 13, 2021
ProTip!
Advisories are also available from the
GraphQL API