GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed...
Moderate
Unreviewed
CVE-2025-23019
was published
Jan 14, 2025
IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification...
Moderate
Unreviewed
CVE-2025-23018
was published
Jan 14, 2025
A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an...
Moderate
Unreviewed
CVE-2024-20390
was published
Sep 11, 2024
An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service...
Moderate
Unreviewed
CVE-2024-40503
was published
Jul 16, 2024
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same...
Moderate
Unreviewed
CVE-2024-37662
was published
Jun 17, 2024
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in...
Moderate
Unreviewed
CVE-2024-37661
was published
Jun 17, 2024
The TTLock App does not employ proper verification procedures to ensure that it is communicating...
Moderate
Unreviewed
CVE-2023-7004
was published
Mar 15, 2024
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks...
Moderate
Unreviewed
CVE-2024-0009
was published
Feb 14, 2024
TAIWAN-CA(TWCA) JCICSecurityTool's Registry-related functions have insufficient filtering for...
Moderate
Unreviewed
CVE-2023-48387
was published
Dec 15, 2023
usememos/memos vulnerable to Improper Verification of Source of a Communication Channel
Moderate
CVE-2022-4848
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
usememos/memos vulnerable to Improper Verification of Source of a Communication Channel
Moderate
CVE-2022-4800
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
Improper Verification of Source of a Communication Channel in Apache Tomcat
Moderate
CVE-2016-0763
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons
Moderate
CVE-2017-5591
was published
for
SleekXMPP
(pip)
May 13, 2022
Improper Verification of Communication Channel in @theia/plugin-ext
Moderate
CVE-2021-41038
was published
for
@theia/plugin-ext
(npm)
Nov 15, 2021
ProTip!
Advisories are also available from the
GraphQL API