GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,638
Erlang
34
GitHub Actions
26
Go
2,249
Maven
5,000+
npm
3,903
NuGet
702
pip
3,671
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
252,913 advisories
Filter by severity
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller -...
Moderate
Unreviewed
CVE-2025-28367
was published
Apr 21, 2025
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management...
Moderate
Unreviewed
CVE-2024-12543
was published
Apr 21, 2025
An improper authorization vulnerability in Dremio Software allows authenticated users to delete...
High
Unreviewed
CVE-2025-2298
was published
Apr 21, 2025
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
Low
Unreviewed
CVE-2025-2517
was published
Apr 21, 2025
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a...
Critical
Unreviewed
CVE-2025-29660
was published
Apr 21, 2025
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function...
Critical
Unreviewed
CVE-2025-29659
was published
Apr 21, 2025
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux...
Moderate
Unreviewed
CVE-2024-12863
was published
Apr 21, 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in...
Moderate
Unreviewed
CVE-2025-28121
was published
Apr 21, 2025
Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a...
Low
Unreviewed
CVE-2025-43916
was published
Apr 21, 2025
Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux...
Moderate
Unreviewed
CVE-2024-12862
was published
Apr 21, 2025
In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A...
High
Unreviewed
CVE-2025-32408
was published
Apr 21, 2025
A buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or...
High
Unreviewed
CVE-2025-29625
was published
Apr 21, 2025
Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows...
Unknown
Unreviewed
CVE-2025-28232
was published
Apr 21, 2025
A vulnerability classified as critical was found in symisc UnQLite up to...
Moderate
Unreviewed
CVE-2025-3791
was published
Apr 21, 2025
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This...
Moderate
Unreviewed
CVE-2025-3792
was published
Apr 21, 2025
Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access...
Unknown
Unreviewed
CVE-2025-28230
was published
Apr 21, 2025
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper...
Moderate
Unreviewed
CVE-2025-2950
was published
Apr 21, 2025
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the...
Unknown
Unreviewed
CVE-2025-29209
was published
Apr 21, 2025
Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows...
Unknown
Unreviewed
CVE-2025-28229
was published
Apr 21, 2025
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01...
Unknown
Unreviewed
CVE-2025-28228
was published
Apr 21, 2025
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based...
Moderate
Unreviewed
CVE-2025-3837
was published
Apr 21, 2025
An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA...
Low
Unreviewed
CVE-2025-3840
was published
Apr 21, 2025
An Improper Authorization vulnerability was identified in the EOL OVA based connect component...
Moderate
Unreviewed
CVE-2025-3838
was published
Apr 21, 2025
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers ...
Unknown
Unreviewed
CVE-2025-25228
was published
Apr 21, 2025
Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW)...
Critical
Unreviewed
CVE-2025-0632
was published
Apr 21, 2025
ProTip!
Advisories are also available from the
GraphQL API