GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,084
Maven
5,000+
npm
3,747
NuGet
674
pip
3,436
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
94,846 advisories
Filter by severity
An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a...
High
Unreviewed
CVE-2024-57618
was published
Jan 14, 2025
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low...
High
Unreviewed
CVE-2024-57726
was published
Jan 16, 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal...
High
Unreviewed
CVE-2024-57727
was published
Jan 16, 2025
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files...
High
Unreviewed
CVE-2024-57728
was published
Jan 16, 2025
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows...
High
Unreviewed
CVE-2012-2897
was published
May 13, 2022
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before...
High
Unreviewed
CVE-2006-2362
was published
May 1, 2022
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers...
High
Unreviewed
CVE-2013-0090
was published
May 5, 2022
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows...
High
Unreviewed
CVE-2013-3894
was published
May 13, 2022
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a...
High
Unreviewed
CVE-2005-2103
was published
May 1, 2022
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute...
High
Unreviewed
CVE-2005-3302
was published
May 1, 2022
** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the...
High
Unreviewed
CVE-2004-2339
was published
Apr 29, 2022
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-23912
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Taras Dashkevych Error Notification allows...
High
Unreviewed
CVE-2025-23902
was published
Jan 16, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-23911
was published
Jan 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-23828
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Shibu Lijack a.k.a CyberJack CJ Custom Content...
High
Unreviewed
CVE-2025-23869
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Chris Roberts Annie allows Cross Site Request...
High
Unreviewed
CVE-2025-23884
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Oliver Schaal GravatarLocalCache allows Cross...
High
Unreviewed
CVE-2025-23901
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Ivo Brett – ApplyMetrics Apply with LinkedIn...
High
Unreviewed
CVE-2025-23898
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Katz Web Services, Inc. Debt Calculator allows...
High
Unreviewed
CVE-2025-23861
was published
Jan 16, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-23915
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in PayForm PayForm allows Stored XSS.This issue...
High
Unreviewed
CVE-2025-23872
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in anmari amr personalise allows Cross Site...
High
Unreviewed
CVE-2025-23880
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Genkisan Genki Announcement allows Cross Site...
High
Unreviewed
CVE-2025-23900
was published
Jan 16, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-23913
was published
Jan 16, 2025
ProTip!
Advisories are also available from the
GraphQL API