GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,339
Erlang
31
GitHub Actions
22
Go
2,099
Maven
5,000+
npm
3,763
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
122,572 advisories
Filter by severity
Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing
Moderate
CVE-2024-23953
was published
for
org.apache.hive:hive-llap-common
(Maven)
Jan 28, 2025
Infinispan vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-0736
was published
for
org.infinispan:infinispan-parent
(Maven)
Jan 28, 2025
The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
Moderate
Unreviewed
CVE-2024-13521
was published
Jan 28, 2025
Cross-site scripting vulnerability exists in Simple Image Sizes 3.2.3 and earlier. If this...
Moderate
Unreviewed
CVE-2025-24810
was published
Jan 28, 2025
NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a...
Moderate
Unreviewed
CVE-2024-0140
was published
Jan 28, 2025
NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory...
Moderate
Unreviewed
CVE-2024-0147
was published
Jan 28, 2025
NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to...
Moderate
Unreviewed
CVE-2024-53881
was published
Jan 28, 2025
NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak...
Moderate
Unreviewed
CVE-2024-53869
was published
Jan 28, 2025
A vulnerability has been identified in Node.js, specifically affecting the handling of drive...
Moderate
Unreviewed
CVE-2025-23084
was published
Jan 28, 2025
The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter...
Moderate
Unreviewed
CVE-2024-12723
was published
Jan 28, 2025
The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of...
Moderate
Unreviewed
CVE-2024-12807
was published
Jan 28, 2025
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an...
Moderate
Unreviewed
CVE-2024-27263
was published
Jan 28, 2025
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted...
Moderate
Unreviewed
CVE-2024-0137
was published
Jan 28, 2025
IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by...
Moderate
Unreviewed
CVE-2024-22315
was published
Jan 28, 2025
The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a...
Moderate
Unreviewed
CVE-2024-45336
was published
Jan 28, 2025
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI...
Moderate
Unreviewed
CVE-2024-45341
was published
Jan 28, 2025
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1
is vulnerable to...
Moderate
Unreviewed
CVE-2023-50316
was published
Jan 28, 2025
IBM QRadar SIEM 7.5 transmits sensitive or security-critical data in cleartext in a communication...
Moderate
Unreviewed
CVE-2024-28786
was published
Jan 28, 2025
An argument injection vulnerability in the diagnose and import pac commands in WatchGuard...
Moderate
Unreviewed
CVE-2022-31749
was published
Jan 28, 2025
Incorrect access control in BYD QIN PLUS DM-i Dilink OS 3.0_13.1.7.2204050.1 allows unauthorized...
Moderate
Unreviewed
CVE-2024-54728
was published
Jan 28, 2025
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the...
Moderate
Unreviewed
CVE-2024-56178
was published
Jan 28, 2025
Cross Site Scripting vulnerability in AdGuard Application v.7.18.1 (4778) and before allows an...
Moderate
Unreviewed
CVE-2024-48662
was published
Jan 28, 2025
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iPadOS...
Moderate
Unreviewed
CVE-2025-24149
was published
Jan 28, 2025
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing...
Moderate
Unreviewed
CVE-2025-24122
was published
Jan 28, 2025
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3,...
Moderate
Unreviewed
CVE-2025-24158
was published
Jan 28, 2025
ProTip!
Advisories are also available from the
GraphQL API