GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
335,515 advisories
Filter by severity
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Moderate
Unreviewed
CVE-2022-21299
was published
Feb 11, 2022
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Moderate
Unreviewed
CVE-2022-21294
was published
Feb 11, 2022
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state...
Moderate
Unreviewed
CVE-2015-2808
was published
May 13, 2022
Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in...
Moderate
Unreviewed
CVE-2015-6564
was published
May 14, 2022
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005...
High
Unreviewed
CVE-2009-0901
was published
May 2, 2022
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly...
High
Unreviewed
CVE-2015-5600
was published
May 13, 2022
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Moderate
Unreviewed
CVE-2022-21293
was published
Feb 11, 2022
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Moderate
Unreviewed
CVE-2022-21283
was published
Feb 11, 2022
The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous...
Low
Unreviewed
CVE-2015-6563
was published
May 14, 2022
SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive...
Unknown
Unreviewed
CVE-2026-38808
was published
May 27, 2026
Command injection in Raynet rvia 12.6.4392.49-amd64.deb allows adversaries to execute commands...
Unknown
Unreviewed
CVE-2025-69600
was published
May 27, 2026
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1...
High
Unreviewed
CVE-2026-5509
was published
May 27, 2026
Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate...
Unknown
Unreviewed
CVE-2026-38807
was published
May 27, 2026
A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function...
Moderate
Unreviewed
CVE-2026-4390
was published
May 27, 2026
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2026-49054
was published
May 27, 2026
A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown...
Moderate
Unreviewed
CVE-2026-4392
was published
May 27, 2026
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
Unknown
Unreviewed
CVE-2025-67903
was published
May 27, 2026
A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability...
Moderate
Unreviewed
CVE-2026-4391
was published
May 27, 2026
Command injection in Raynet rvia version 12.6.4392.49-amd64.deb allows adversaries to execute...
High
Unreviewed
CVE-2026-38945
was published
May 27, 2026
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2022-41656
was published
May 27, 2026
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown...
Unknown
Unreviewed
CVE-2025-70116
was published
May 27, 2026
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a...
Moderate
Unreviewed
CVE-2026-48927
was published
May 27, 2026
OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template...
Unknown
Unreviewed
CVE-2026-38930
was published
May 27, 2026
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical...
Unknown
Unreviewed
CVE-2025-68712
was published
May 27, 2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d...
Moderate
Unreviewed
CVE-2026-9674
was published
May 27, 2026
ProTip!
Advisories are also available from the
GraphQL API