GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,575
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,523
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
24 advisories
Filter by severity
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox...
Critical
Unreviewed
CVE-2026-65093
was published
Aug 25, 2026
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in...
Critical
Unreviewed
CVE-2024-58377
was published
Aug 25, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-16860
was published
Aug 12, 2026
RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control...
Critical
Unreviewed
CVE-2025-69599
was published
May 8, 2026
The vulnerability, if exploited, could allow an authenticated miscreant
(OS Standard User) to...
Critical
Unreviewed
CVE-2025-65118
was published
Jan 16, 2026
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could...
Critical
Unreviewed
CVE-2025-65741
was published
Dec 9, 2025
When the service of ABP and AES is installed in a directory writable by non-administrative users,...
Critical
Unreviewed
CVE-2025-13051
was published
Nov 19, 2025
Mattermost allows authenticated users to write files to arbitrary locations
Critical
CVE-2025-4981
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for...
Critical
Unreviewed
CVE-2024-23054
was published
Feb 5, 2024
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the...
Critical
Unreviewed
CVE-2023-37490
was published
Aug 8, 2023
pipreqs vulnerable to Dependency Confusion
Critical
CVE-2023-31543
was published
for
pipreqs
(pip)
Jun 30, 2023
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer...
Critical
Unreviewed
CVE-2023-25143
was published
Mar 10, 2023
Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5...
Critical
Unreviewed
CVE-2022-34825
was published
Nov 9, 2022
A vulnerability was found in Redis. It has been declared as critical. This vulnerability affects...
Critical
Unreviewed
CVE-2022-3734
was published
Oct 28, 2022
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability....
Critical
Unreviewed
CVE-2018-12805
was published
May 13, 2022
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote...
Critical
Unreviewed
CVE-2017-6517
was published
May 13, 2022
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading...
Critical
Unreviewed
CVE-2017-3090
was published
May 13, 2022
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading...
Critical
Unreviewed
CVE-2017-3092
was published
May 13, 2022
Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading...
Critical
Unreviewed
CVE-2017-3097
was published
May 13, 2022
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ...
Critical
Unreviewed
CVE-2019-9546
was published
May 13, 2022
The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load...
Critical
Unreviewed
CVE-2019-7653
was published
May 13, 2022
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search...
Critical
Unreviewed
CVE-2022-24955
was published
Feb 12, 2022
Git LFS can execute a Git binary from the current directory
Critical
CVE-2020-27955
was published
for
github.com/git-lfs/git-lfs
(Go)
Feb 11, 2022
Arbitrary code execution due to an uncontrolled search path for the git binary
Critical
CVE-2021-28955
was published
for
github.com/MichaelMure/git-bug
(Go)
May 25, 2021
ProTip!
Advisories are also available from the
GraphQL API