GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
179 advisories
Filter by severity
The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers...
Moderate
Unreviewed
CVE-2025-52622
was published
Dec 2, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Ray's New Token Authentication is Disabled By Default
Critical
CVE-2025-34351
was published
for
ray
(pip)
Nov 27, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
The default configuration of WatchGuard Firebox devices through 2025-09-10 allows administrative...
Critical
Unreviewed
CVE-2025-59396
was published
Nov 6, 2025
By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker...
Moderate
Unreviewed
CVE-2025-35021
was published
Nov 4, 2025
Jenkins Eggplant Runner Plugin protection mechanism disabled
Moderate
CVE-2025-64135
was published
for
io.jenkins.plugins:eggplant-runner
(Maven)
Oct 29, 2025
In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Fix...
Moderate
Unreviewed
CVE-2022-49099
was published
Oct 14, 2025
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with...
Moderate
Unreviewed
CVE-2025-41245
was published
Sep 29, 2025
Liferay has Insecure Default Initialization of Resource issue
Moderate
CVE-2025-43797
was published
for
com.liferay:com.liferay.site.admin.web
(Maven)
Sep 16, 2025
During a short time frame while the device is booting an unauthenticated remote attacker can send...
Moderate
Unreviewed
CVE-2025-41713
was published
Sep 15, 2025
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for...
High
Unreviewed
CVE-2025-36222
was published
Sep 11, 2025
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept...
Moderate
Unreviewed
CVE-2025-32330
was published
Sep 4, 2025
In the Linux kernel, the following vulnerability has been resolved:
cifs: Fix the smbd_response...
Moderate
Unreviewed
CVE-2025-38523
was published
Aug 16, 2025
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation...
Critical
Unreviewed
CVE-2025-7353
was published
Aug 14, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk...
High
Unreviewed
CVE-2025-44647
was published
Jul 21, 2025
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure...
High
Unreviewed
CVE-2025-25271
was published
Jul 8, 2025
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain...
Critical
Unreviewed
CVE-2025-41672
was published
Jul 7, 2025
Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
Moderate
CVE-2025-53602
was published
for
io.zipkin:zipkin-server
(Maven)
Jul 4, 2025
The Versa Director software exposes a number of services by default and allow attackers an easy...
Critical
Unreviewed
CVE-2025-24288
was published
Jun 19, 2025
The CS5000 Fire Panel is vulnerable due to a default account that exists
on the panel. Even...
Critical
Unreviewed
CVE-2025-41438
was published
May 30, 2025
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap...
Moderate
Unreviewed
CVE-2025-48927
was published
May 28, 2025
A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All...
High
Unreviewed
CVE-2025-31930
was published
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API