GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,079
Maven
5,000+
npm
3,747
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
21,137 advisories
Filter by severity
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above....
Critical
Unreviewed
CVE-2025-0471
was published
Jan 16, 2025
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing...
Critical
Unreviewed
CVE-2025-0456
was published
Jan 16, 2025
The airPASS from NetVision Information has a SQL Injection vulnerability, allowing...
Critical
Unreviewed
CVE-2025-0455
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the...
Critical
Unreviewed
CVE-2025-22907
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform...
Critical
Unreviewed
CVE-2025-22912
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName...
Critical
Unreviewed
CVE-2025-22906
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter...
Critical
Unreviewed
CVE-2025-22905
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the...
Critical
Unreviewed
CVE-2025-22913
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the...
Critical
Unreviewed
CVE-2025-22916
was published
Jan 16, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and...
Critical
Unreviewed
CVE-2024-44136
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57014
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57015
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57016
was published
Jan 15, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List...
Critical
Unreviewed
CVE-2025-22782
was published
Jan 15, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-22785
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57013
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57011
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57012
was published
Jan 15, 2025
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper...
Critical
Unreviewed
CVE-2024-12084
was published
Jan 15, 2025
Moxa’s Ethernet switch EDS-508A Series, running firmware version 3.11 and earlier, is vulnerable...
Critical
Unreviewed
CVE-2024-12297
was published
Jan 15, 2025
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in...
Critical
Unreviewed
CVE-2024-9636
was published
Jan 15, 2025
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an...
Critical
Unreviewed
CVE-2024-48856
was published
Jan 14, 2025
Windows OLE Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2025-21298
was published
Jan 14, 2025
Windows NTLM V1 Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2025-21311
was published
Jan 14, 2025
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2025-21307
was published
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API