GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,782
Erlang
36
GitHub Actions
29
Go
2,346
Maven
5,000+
npm
3,976
NuGet
720
pip
3,772
Pub
12
RubyGems
923
Rust
980
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,817 advisories
Filter by severity
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-37743
was published
Jun 24, 2025
On a client with a non-admin user, a script can be integrated into a report. The reports could...
Critical
Unreviewed
CVE-2025-6512
was published
Jun 23, 2025
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary...
Moderate
Unreviewed
CVE-2025-24287
was published
Jun 19, 2025
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated...
Critical
Unreviewed
CVE-2025-23121
was published
Jun 19, 2025
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a...
High
Unreviewed
CVE-2025-5309
was published
Jun 16, 2025
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is...
Moderate
Unreviewed
CVE-2025-6101
was published
Jun 16, 2025
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS...
Critical
Unreviewed
CVE-2025-28386
was published
Jun 13, 2025
Remote code execution that allows unauthorized users to execute arbitrary code on the server...
Critical
Unreviewed
CVE-2025-29902
was published
Jun 13, 2025
Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was...
Critical
Unreviewed
CVE-2025-30085
was published
Jun 11, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi...
Critical
Unreviewed
CVE-2025-48140
was published
Jun 9, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering...
Critical
Unreviewed
CVE-2025-48123
was published
Jun 9, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase...
Moderate
Unreviewed
CVE-2025-49250
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41362
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41365
was published
Jun 6, 2025
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0...
High
Unreviewed
CVE-2025-25021
was published
Jun 3, 2025
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result...
Critical
Unreviewed
CVE-2025-32106
was published
Jun 3, 2025
Kea configuration and API directives can be used to load a malicious hook library. Many common...
High
Unreviewed
CVE-2025-32801
was published
May 28, 2025
A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This...
Moderate
Unreviewed
CVE-2025-5151
was published
May 25, 2025
A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an...
Moderate
Unreviewed
CVE-2025-5137
was published
May 25, 2025
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-51360
was published
May 23, 2025
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential...
High
Unreviewed
CVE-2024-13952
was published
May 22, 2025
Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials...
High
Unreviewed
CVE-2024-9639
was published
May 22, 2025
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database...
High
Unreviewed
CVE-2024-13928
was published
May 22, 2025
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator...
High
Unreviewed
CVE-2024-13929
was published
May 22, 2025
Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials...
High
Unreviewed
CVE-2025-30172
was published
May 22, 2025
ProTip!
Advisories are also available from the
GraphQL API