GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,638
Erlang
34
GitHub Actions
26
Go
2,249
Maven
5,000+
npm
3,903
NuGet
702
pip
3,671
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
252,905 advisories
Filter by severity
A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-3843
was published
Apr 22, 2025
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0....
Moderate
Unreviewed
CVE-2025-3849
was published
Apr 22, 2025
A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-3845
was published
Apr 22, 2025
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may...
Low
Unreviewed
CVE-2025-2987
was published
Apr 22, 2025
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-3846
was published
Apr 22, 2025
A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This...
Moderate
Unreviewed
CVE-2025-3847
was published
Apr 22, 2025
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to...
Moderate
Unreviewed
CVE-2025-3841
was published
Apr 21, 2025
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects...
Moderate
Unreviewed
CVE-2025-3842
was published
Apr 21, 2025
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0...
Unknown
Unreviewed
CVE-2024-57394
was published
Apr 21, 2025
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a...
Unknown
Unreviewed
CVE-2025-28104
was published
Apr 21, 2025
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an...
High
Unreviewed
CVE-2025-43922
was published
Apr 21, 2025
open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.
Unknown
Unreviewed
CVE-2025-29446
was published
Apr 21, 2025
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
High
Unreviewed
CVE-2025-23174
was published
Apr 21, 2025
opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage...
Unknown
Unreviewed
CVE-2025-28099
was published
Apr 21, 2025
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute...
Moderate
Unreviewed
CVE-2025-28102
was published
Apr 21, 2025
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts...
Unknown
Unreviewed
CVE-2025-28103
was published
Apr 21, 2025
Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue...
Unknown
Unreviewed
CVE-2025-27086
was published
Apr 21, 2025
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller -...
Moderate
Unreviewed
CVE-2025-28367
was published
Apr 21, 2025
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management...
Moderate
Unreviewed
CVE-2024-12543
was published
Apr 21, 2025
An improper authorization vulnerability in Dremio Software allows authenticated users to delete...
High
Unreviewed
CVE-2025-2298
was published
Apr 21, 2025
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
Low
Unreviewed
CVE-2025-2517
was published
Apr 21, 2025
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a...
Critical
Unreviewed
CVE-2025-29660
was published
Apr 21, 2025
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function...
Critical
Unreviewed
CVE-2025-29659
was published
Apr 21, 2025
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux...
Moderate
Unreviewed
CVE-2024-12863
was published
Apr 21, 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in...
Moderate
Unreviewed
CVE-2025-28121
was published
Apr 21, 2025
ProTip!
Advisories are also available from the
GraphQL API