GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,538
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
36 advisories
Filter by severity
Xenstore, to have an up-to-date picture of the entire system, wants to
know of domains appearing...
High
Unreviewed
CVE-2026-42492
was published
Jul 28, 2026
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system...
High
Unreviewed
CVE-2026-7639
was published
Jul 10, 2026
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
High
CVE-2026-52736
was published
for
zebra-state
(Rust)
Jul 2, 2026
Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain...
High
Unreviewed
CVE-2025-66467
was published
May 8, 2026
Multer vulnerable to Denial of Service via incomplete cleanup
High
CVE-2026-3304
was published
for
multer
(npm)
Mar 1, 2026
Apache Struts has a Denial of Service vulnerability
High
CVE-2025-66675
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 10, 2025
Apache Struts is Vulnerable to DoS via File Leak
High
CVE-2025-64775
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 1, 2025
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
High
Unreviewed
CVE-2025-60730
was published
Oct 24, 2025
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS...
High
Unreviewed
CVE-2025-59781
was published
Oct 15, 2025
Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local...
High
Unreviewed
CVE-2025-0032
was published
Sep 6, 2025
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute...
High
Unreviewed
CVE-2025-43711
was published
Jul 5, 2025
In the Linux kernel, the following vulnerability has been resolved:
mm, slab: clean up slab-...
High
Unreviewed
CVE-2025-37908
was published
May 20, 2025
SiYuan has an arbitrary file deletion vulnerability
High
CVE-2025-21609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jan 3, 2025
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless...
High
Unreviewed
CVE-2024-20303
was published
Mar 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
x86/kvm: Disable kvmclock on...
High
Unreviewed
CVE-2021-47110
was published
Mar 15, 2024
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
High
CVE-2023-41835
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 5, 2023
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount...
High
Unreviewed
CVE-2022-3238
was published
Jul 6, 2023
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4...
High
Unreviewed
CVE-2023-0836
was published
Mar 29, 2023
redis-py Race Condition due to incomplete fix
High
CVE-2023-28859
was published
for
redis
(pip)
Mar 26, 2023
Local privilege escalation due to incomplete uninstallation cleanup. The following products are...
High
Unreviewed
CVE-2022-45455
was published
Feb 13, 2023
Incomplete cleanup in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146...
High
Unreviewed
CVE-2022-27639
was published
Nov 11, 2022
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore...
High
Unreviewed
CVE-2022-42320
was published
Nov 1, 2022
Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially...
High
Unreviewed
CVE-2020-24489
was published
May 24, 2022
There is an unsafe incomplete reset of PATH in OpenDoas 6.6 through 6.8 when changing the user...
High
Unreviewed
CVE-2019-25016
was published
May 24, 2022
Flarum mishandles invalidation of user email tokens
High
CVE-2019-11514
was published
for
flarum/flarum
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API