GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,915 advisories
Filter by severity
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Moderate
CVE-2025-1767
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Moderate
CVE-2024-9042
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
Moderate
CVE-2025-22870
was published
for
golang.org/x/net
(Go)
Mar 12, 2025
Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F...
High
Unreviewed
CVE-2024-26290
was published
Mar 12, 2025
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000...
High
Unreviewed
CVE-2025-20146
was published
Mar 12, 2025
A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy...
High
Unreviewed
CVE-2025-20142
was published
Mar 12, 2025
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9),...
Critical
Unreviewed
CVE-2025-27494
was published
Mar 11, 2025
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9),...
Critical
Unreviewed
CVE-2025-27493
was published
Mar 11, 2025
Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue...
Moderate
Unreviewed
CVE-2025-26702
was published
Mar 11, 2025
Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality
Moderate
CVE-2025-0660
was published
for
concrete5/concrete5
(Composer)
Mar 10, 2025
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60...
Moderate
Unreviewed
CVE-2025-27253
was published
Mar 10, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
GHSA-2gh3-rmm4-6rq5
was published
for
protobuf
(Rust)
Mar 7, 2025
A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue...
Moderate
Unreviewed
CVE-2025-2043
was published
Mar 7, 2025
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache...
Moderate
Unreviewed
CVE-2024-38311
was published
Mar 6, 2025
Volt Allows RCE Via User-Crafted Requests
Critical
CVE-2025-27517
was published
for
livewire/volt
(Composer)
Mar 5, 2025
The WooCommerce Recover Abandoned Cart plugin for WordPress is vulnerable to PHP Object Injection...
High
Unreviewed
CVE-2025-0956
was published
Mar 5, 2025
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS...
High
Unreviewed
CVE-2025-1080
was published
Mar 4, 2025
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access...
Moderate
Unreviewed
CVE-2025-0958
was published
Mar 4, 2025
Permission verification bypass vulnerability in the notification module
Impact: Successful...
High
Unreviewed
CVE-2024-58044
was published
Mar 4, 2025
Paragon Partition Manager version 17, both community and Business versions, contain an insecure...
High
Unreviewed
CVE-2025-0289
was published
Mar 3, 2025
Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory mapping vulnerability...
High
Unreviewed
CVE-2025-0285
was published
Mar 3, 2025
Memory corruption while processing input message passed from FE driver.
High
Unreviewed
CVE-2024-53030
was published
Mar 3, 2025
Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.
High
Unreviewed
CVE-2024-53031
was published
Mar 3, 2025
Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.
High
Unreviewed
CVE-2024-53029
was published
Mar 3, 2025
Memory corruption may occur during communication between primary and guest VM.
High
Unreviewed
CVE-2024-53022
was published
Mar 3, 2025
ProTip!
Advisories are also available from the
GraphQL API