GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,203
Maven
5,000+
npm
3,857
NuGet
696
pip
3,639
Pub
12
RubyGems
912
Rust
913
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
97,638 advisories
Filter by severity
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS...
High
Unreviewed
CVE-2025-30349
was published
Mar 21, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2024-49563
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2024-49564
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24378
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2024-49601
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2024-49565
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24386
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24385
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-23383
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open...
High
Unreviewed
CVE-2025-24381
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24379
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24380
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24382
was published
Mar 28, 2025
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements...
High
Unreviewed
CVE-2025-24377
was published
Mar 28, 2025
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to...
High
Unreviewed
CVE-2025-30232
was published
Mar 28, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-26890
was published
Mar 28, 2025
Missing Authorization vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a...
High
Unreviewed
CVE-2025-26956
was published
Mar 28, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-26874
was published
Mar 28, 2025
A flaw was found in grub2. During the network boot process, when trying to search for the...
High
Unreviewed
CVE-2025-0624
was published
Feb 19, 2025
Missing Authorization vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a...
High
Unreviewed
CVE-2025-26733
was published
Mar 28, 2025
SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a...
High
Unreviewed
CVE-2024-22983
was published
Feb 29, 2024
Paragon Partition Manager version 7.9.1 contains an arbitrary kernel memory write vulnerability...
High
Unreviewed
CVE-2025-0286
was published
Mar 3, 2025
Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based...
High
Unreviewed
CVE-2024-29390
was published
Jun 20, 2024
tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain...
High
Unreviewed
CVE-2024-36070
was published
May 19, 2024
Because of a logical error in XSA-407 (Branch Type Confusion), the
mitigation is not applied...
High
Unreviewed
CVE-2024-31142
was published
May 16, 2024
ProTip!
Advisories are also available from the
GraphQL API