GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,957
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
352 advisories
Filter by severity
A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41....
High
Unreviewed
CVE-2025-7883
was published
Jul 20, 2025
A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and...
High
Unreviewed
CVE-2025-7350
was published
Sep 9, 2025
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to...
High
Unreviewed
CVE-2024-43388
was published
Sep 10, 2024
A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when...
High
Unreviewed
CVE-2020-1481
was published
May 24, 2022
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive...
High
Unreviewed
CVE-2024-12756
was published
Feb 11, 2025
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user...
High
Unreviewed
CVE-2023-25719
was published
Feb 13, 2023
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0...
High
Unreviewed
CVE-2025-47867
was published
Jun 17, 2025
A vulnerability classified as critical was found in FLIR AX8 up to 1.46.16. This vulnerability...
High
Unreviewed
CVE-2025-5126
was published
May 24, 2025
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16...
High
Unreviewed
CVE-2025-0528
was published
Jan 17, 2025
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options....
High
Unreviewed
CVE-2022-37027
was published
Sep 22, 2022
A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0...
High
Unreviewed
CVE-2023-1059
was published
Feb 27, 2023
A vulnerability, which was classified as critical, has been found in SourceCodester Doctors...
High
Unreviewed
CVE-2023-1061
was published
Feb 27, 2023
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4...
High
Unreviewed
CVE-2022-2992
was published
Oct 17, 2022
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all...
High
Unreviewed
CVE-2022-3060
was published
Oct 17, 2022
A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This...
High
Unreviewed
CVE-2025-4349
was published
May 6, 2025
A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This...
High
Unreviewed
CVE-2025-4350
was published
May 6, 2025
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and...
High
Unreviewed
CVE-2022-35507
was published
Dec 4, 2022
sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the...
High
Unreviewed
CVE-2017-17512
was published
May 14, 2022
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program...
High
Unreviewed
CVE-2017-17523
was published
May 14, 2022
Two potential audit log injections in SAP HANA extended application services 1.0, advanced model:...
High
Unreviewed
CVE-2017-16680
was published
May 14, 2022
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary ...
High
Unreviewed
CVE-2015-4075
was published
May 13, 2022
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An ...
High
Unreviewed
CVE-2017-6031
was published
May 13, 2022
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by...
High
Unreviewed
CVE-2017-7703
was published
May 14, 2022
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products ...
High
Unreviewed
CVE-2017-3547
was published
May 13, 2022
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify...
High
Unreviewed
CVE-2015-8258
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API