GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
287,880 advisories
Filter by severity
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime...
High
Unreviewed
CVE-2025-41659
was published
Aug 4, 2025
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS...
High
Unreviewed
CVE-2025-41691
was published
Aug 4, 2025
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without...
Unknown
Unreviewed
CVE-2025-20701
was published
Aug 4, 2025
Grafana is an open-source platform for monitoring and observability. The Infinity datasource...
Moderate
Unreviewed
CVE-2025-8341
was published
Aug 4, 2025
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged...
Moderate
Unreviewed
CVE-2025-41658
was published
Aug 4, 2025
In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access...
Unknown
Unreviewed
CVE-2025-20700
was published
Aug 4, 2025
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol....
Unknown
Unreviewed
CVE-2025-20702
was published
Aug 4, 2025
Out-of-bounds write vulnerability exists in FUJIFILM Business Innovation MFPs. A specially...
Moderate
Unreviewed
CVE-2025-48499
was published
Aug 4, 2025
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could...
Unknown
Unreviewed
CVE-2025-20697
was published
Aug 4, 2025
/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload...
Moderate
Unreviewed
CVE-2025-54962
was published
Aug 4, 2025
In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could...
Unknown
Unreviewed
CVE-2025-20698
was published
Aug 4, 2025
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to...
Unknown
Unreviewed
CVE-2025-20696
was published
Aug 4, 2025
langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the...
Critical
Unreviewed
CVE-2025-46059
was published
Jul 29, 2025
The gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the...
Low
Unreviewed
CVE-2025-54956
was published
Aug 3, 2025
A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected...
Moderate
Unreviewed
CVE-2025-8509
was published
Aug 3, 2025
A vulnerability classified as problematic has been found in Portabilis i-Educar 2.10. This...
Moderate
Unreviewed
CVE-2025-8510
was published
Aug 3, 2025
A vulnerability classified as problematic was found in Portabilis i-Diario 1.5.0. This...
Moderate
Unreviewed
CVE-2025-8511
was published
Aug 3, 2025
A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on...
Moderate
Unreviewed
CVE-2025-8513
was published
Aug 3, 2025
A vulnerability, which was classified as problematic, has been found in TVB Big Big Shop App 2.9...
Moderate
Unreviewed
CVE-2025-8512
was published
Aug 3, 2025
A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-8507
was published
Aug 3, 2025
A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic....
Moderate
Unreviewed
CVE-2025-8508
was published
Aug 3, 2025
Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin.
This issue...
Unknown
Unreviewed
CVE-2024-41177
was published
Aug 3, 2025
Improper Input Validation vulnerability in Apache Zeppelin. The fix for JDBC URL validation in...
Unknown
Unreviewed
CVE-2024-52279
was published
Aug 3, 2025
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin.
The attacker could...
Unknown
Unreviewed
CVE-2024-51775
was published
Aug 3, 2025
A vulnerability classified as critical has been found in Engeman Web up to 12.0.0.1. Affected is...
Moderate
Unreviewed
CVE-2025-8220
was published
Jul 27, 2025
ProTip!
Advisories are also available from the
GraphQL API