GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,362
Erlang
33
GitHub Actions
22
Go
2,131
Maven
5,000+
npm
3,795
NuGet
686
pip
3,473
Pub
12
RubyGems
896
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,083 advisories
Filter by severity
The MediaProvider module has a vulnerability in permission verification. Successful exploitation...
High
Unreviewed
CVE-2022-48347
was published
Mar 28, 2023
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this...
High
Unreviewed
CVE-2022-48346
was published
Mar 28, 2023
A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series...
Moderate
Unreviewed
CVE-2025-20158
was published
Feb 19, 2025
FFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component...
Moderate
Unreviewed
CVE-2025-25468
was published
Feb 19, 2025
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4...
High
Unreviewed
CVE-2023-0836
was published
Mar 29, 2023
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-13609
was published
Feb 18, 2025
The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive...
High
Unreviewed
CVE-2024-13622
was published
Feb 18, 2025
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2024-13525
was published
Feb 15, 2025
An issue was discovered in the GrowthExperiments extension for MediaWiki through 1.39.3. The...
Moderate
Unreviewed
CVE-2023-29137
was published
Mar 31, 2023
An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote...
High
Unreviewed
CVE-2024-51123
was published
Feb 13, 2025
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes...
Moderate
Unreviewed
CVE-2021-25369
was published
May 24, 2022
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet...
Moderate
Unreviewed
CVE-2024-13641
was published
Feb 14, 2025
An attacker may modify the URL to discover sensitive information about the target network.
High
Unreviewed
CVE-2025-25281
was published
Feb 14, 2025
Apache ServiceComb Service-Center Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2023-44312
was published
for
github.com/apache/servicecomb-service-center
(Go)
Jan 31, 2024
Apache Storm Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files
Moderate
CVE-2023-43123
was published
for
org.apache.storm:storm-core
(Maven)
Nov 23, 2023
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2023-42505
was published
for
apache-superset
(pip)
Nov 28, 2023
Synapse vulnerable to leak of remote user device information
Moderate
CVE-2023-43796
was published
for
matrix-synapse
(pip)
Oct 31, 2023
urllib3's request body not stripped after redirect from 303 status changes request method to GET
Moderate
CVE-2023-45803
was published
for
urllib3
(pip)
Oct 17, 2023
Apache Airflow vulnerable to sensitive information exposure
Moderate
CVE-2023-42663
was published
for
apache-airflow
(pip)
Oct 14, 2023
MongoDB Driver may publish events containing authentication-related data
Moderate
CVE-2021-32050
was published
for
github.com/mongodb/mongo-swift-driver
(Composer)
Aug 29, 2023
Apache Airflow denial of service vulnerability
High
CVE-2023-37379
was published
for
apache-airflow
(pip)
Aug 23, 2023
Apache Airflow Execution with Unnecessary Privileges
High
CVE-2023-39508
was published
for
apache-airflow
(pip)
Aug 5, 2023
Apache ZooKeeper vulnerable to information disclosure in persistent watchers handling
Moderate
CVE-2024-23944
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Mar 15, 2024
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Low
CVE-2024-30260
was published
for
undici
(npm)
Apr 4, 2024
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This
...
Moderate
Unreviewed
CVE-2023-45236
was published
Jan 16, 2024
ProTip!
Advisories are also available from the
GraphQL API