GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,967
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,037
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
539 advisories
Filter by severity
A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the...
Moderate
Unreviewed
CVE-2025-8259
was published
Jul 28, 2025
gix-transport code execution vulnerability
Moderate
CVE-2023-53158
was published
for
gix-transport
(Rust)
Sep 25, 2023
Duplicate Advisory: gix-transport code execution vulnerability
Moderate
GHSA-5c5j-jmhx-q2gr
was published
for
gix-transport
(Rust)
Jul 28, 2025
•
withdrawn
Calibre Web and Autocaliweb have OS Command Injection vulnerability
Moderate
CVE-2025-7404
was published
for
calibreweb
(pip)
Jul 24, 2025
A vulnerability classified as critical has been found in D-Link DIR-818LW up to 20191215. This...
Moderate
Unreviewed
CVE-2025-7553
was published
Jul 14, 2025
A vulnerability, which was classified as critical, was found in Tenda AC7 1200M 15.03.06.44....
Moderate
Unreviewed
CVE-2025-1819
was published
Mar 2, 2025
Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated...
Moderate
Unreviewed
CVE-2025-52379
was published
Jul 15, 2025
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version...
Moderate
Unreviewed
CVE-2025-52089
was published
Jul 11, 2025
phpThumb is vulnerable to Command Injection through its gif_outputAsJpeg function
Moderate
CVE-2025-52994
was published
for
james-heinrich/phpthumb
(Composer)
Jul 11, 2025
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that...
Moderate
Unreviewed
CVE-2025-20319
was published
Jul 7, 2025
A physical attacker with no privileges can gain full control of the affected device due to...
Moderate
Unreviewed
CVE-2025-3705
was published
Jul 7, 2025
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell...
Moderate
Unreviewed
CVE-2025-47228
was published
Jul 5, 2025
A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate...
Moderate
Unreviewed
CVE-2025-20308
was published
Jul 2, 2025
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013...
Moderate
Unreviewed
CVE-2025-5447
was published
Jun 2, 2025
A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this...
Moderate
Unreviewed
CVE-2025-6897
was published
Jun 30, 2025
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected...
Moderate
Unreviewed
CVE-2025-6620
was published
Jun 26, 2025
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical....
Moderate
Unreviewed
CVE-2025-6618
was published
Jun 26, 2025
A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This...
Moderate
Unreviewed
CVE-2025-6621
was published
Jun 26, 2025
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-6619
was published
Jun 26, 2025
iOS Simulator MCP Command Injection allowed via exec API
Moderate
CVE-2025-52573
was published
for
ios-simulator-mcp
(npm)
Jun 26, 2025
Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who...
Moderate
Unreviewed
CVE-2024-22366
was published
Jan 24, 2024
A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0...
Moderate
Unreviewed
CVE-2025-5444
was published
Jun 2, 2025
A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300,...
Moderate
Unreviewed
CVE-2025-5443
was published
Jun 2, 2025
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013...
Moderate
Unreviewed
CVE-2025-5445
was published
Jun 2, 2025
A vulnerability was found in D-Link DCS-932L 2.18.01. It has been rated as critical. Affected by...
Moderate
Unreviewed
CVE-2025-5573
was published
Jun 4, 2025
ProTip!
Advisories are also available from the
GraphQL API