GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
24,580 advisories
Filter by severity
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever...
Critical
Unreviewed
CVE-2024-36554
was published
Feb 6, 2025
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1...
Critical
Unreviewed
CVE-2024-36555
was published
Feb 6, 2025
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever...
Critical
Unreviewed
CVE-2024-36556
was published
Feb 6, 2025
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
Critical
CVE-2025-24981
was published
for
@nuxtjs/mdc
(npm)
Feb 6, 2025
Multiple rtmpdump vulnerabilities
Critical
GHSA-vrpv-vw92-328g
was published
for
rudloff/rtmpdump-bin
(Composer)
Feb 6, 2025
Honeywell OneWireless
Wireless Device Manager (WDM) for the following versions R310.x, R320.x,...
Critical
Unreviewed
CVE-2023-5878
was published
Feb 6, 2025
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an...
Critical
Unreviewed
CVE-2025-0982
was published
Feb 6, 2025
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker...
Critical
Unreviewed
CVE-2024-51450
was published
Feb 6, 2025
OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for...
Critical
Unreviewed
CVE-2025-1066
was published
Feb 6, 2025
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB...
Critical
Unreviewed
CVE-2024-51547
was published
Feb 6, 2025
utils-extend Prototype Pollution
Critical
CVE-2024-57077
was published
for
utils-extend
(npm)
Feb 6, 2025
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-57520
was published
Feb 6, 2025
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote...
Critical
Unreviewed
CVE-2020-36084
was published
Feb 6, 2025
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
Critical
GHSA-9x4v-xfq5-m8x5
was published
for
better-auth
(npm)
Feb 5, 2025
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid...
Critical
Unreviewed
CVE-2025-20125
was published
Feb 5, 2025
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute...
Critical
Unreviewed
CVE-2025-20124
was published
Feb 5, 2025
GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
Critical
CVE-2024-36404
was published
for
org.geotools.xsd:gt-xsd-core
(Maven)
Feb 5, 2025
libcurl would wrongly close the same eventfd file descriptor twice when taking
down a connection...
Critical
Unreviewed
CVE-2025-0665
was published
Feb 5, 2025
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute...
Critical
Unreviewed
CVE-2025-23114
was published
Feb 5, 2025
An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-48445
was published
Feb 5, 2025
AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which...
Critical
Unreviewed
CVE-2025-0960
was published
Feb 4, 2025
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2025-0364
was published
Feb 4, 2025
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Critical
CVE-2025-24964
was published
for
vitest
(npm)
Feb 4, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page...
Critical
Unreviewed
CVE-2025-24677
was published
Feb 4, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-22699
was published
Feb 4, 2025
ProTip!
Advisories are also available from the
GraphQL API