GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
764 advisories
Filter by severity
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer...
High
Unreviewed
CVE-2023-53875
was published
Dec 15, 2025
IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 Deploy transmits data in clear text that could...
Moderate
Unreviewed
CVE-2025-13489
was published
Dec 15, 2025
The mobile application is configured to allow clear text traffic to all domains and communicates...
Critical
Unreviewed
CVE-2025-65827
was published
Dec 10, 2025
Solstice Pod API (version 5.5, 6.2) contains an unauthenticated API endpoint (`/api/config`) that...
Moderate
Unreviewed
CVE-2025-66573
was published
Dec 4, 2025
Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2...
High
Unreviewed
CVE-2025-63364
was published
Dec 4, 2025
Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over...
Moderate
Unreviewed
CVE-2024-32384
was published
Dec 1, 2025
A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS...
Moderate
Unreviewed
CVE-2024-48894
was published
Dec 1, 2025
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution...
Low
Unreviewed
CVE-2025-63292
was published
Nov 17, 2025
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability...
High
Unreviewed
CVE-2025-62765
was published
Nov 15, 2025
When using domain users as BRAIN2 users, communication with Active Directory services is...
High
Unreviewed
CVE-2025-12508
was published
Oct 31, 2025
The web server of the device performs exchanges of sensitive information in clear text through an...
High
Unreviewed
CVE-2025-64389
was published
Oct 31, 2025
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager...
High
Unreviewed
CVE-2025-34271
was published
Oct 31, 2025
All WorkExaminer Professional traffic between monitoring client, console and server is...
High
Unreviewed
CVE-2025-10641
was published
Oct 21, 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits...
Low
Unreviewed
CVE-2025-62643
was published
Oct 17, 2025
In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of...
Critical
Unreviewed
CVE-2025-11492
was published
Oct 16, 2025
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker...
High
Unreviewed
CVE-2025-53139
was published
Oct 14, 2025
A cleartext transmission of sensitive information vulnerability in the affected products allows...
High
Unreviewed
CVE-2025-41718
was published
Oct 14, 2025
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. This affects an unknown function...
Low
Unreviewed
CVE-2025-11640
was published
Oct 12, 2025
Components of the YoSmart YoLink ecosystem through 2025-10-02 leverage unencrypted MQTT to...
Moderate
Unreviewed
CVE-2025-59448
was published
Oct 6, 2025
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed...
Moderate
Unreviewed
CVE-2025-59406
was published
Oct 2, 2025
IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily...
High
Unreviewed
CVE-2025-36274
was published
Sep 26, 2025
iMonitor EAM 9.6394 transmits communication between the EAM client agent and the EAM server, as...
Moderate
Unreviewed
CVE-2025-10540
was published
Sep 25, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and...
Critical
Unreviewed
CVE-2025-34199
was published
Sep 19, 2025
Cognex In-Sight Explorer and In-Sight Camera Firmware expose
a proprietary protocol on TCP port...
High
Unreviewed
CVE-2025-54818
was published
Sep 19, 2025
An adjacent attacker without authentication can exploit this
vulnerability to retrieve a set of...
High
Unreviewed
CVE-2025-47698
was published
Sep 18, 2025
ProTip!
Advisories are also available from the
GraphQL API