GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
50 advisories
Filter by severity
The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications...
High
Unreviewed
CVE-2026-12991
was published
Jul 27, 2026
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2)...
Moderate
Unreviewed
CVE-2026-23811
was published
Mar 4, 2026
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and...
Moderate
Unreviewed
CVE-2026-23810
was published
Mar 4, 2026
A vulnerability has been identified where an attacker connecting to an access point as a standard...
Moderate
Unreviewed
CVE-2026-23812
was published
Mar 4, 2026
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions)...
High
Unreviewed
CVE-2025-40770
was published
Aug 12, 2025
A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0...
Moderate
Unreviewed
CVE-2024-50568
was published
Jun 10, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 18.5 and...
High
Unreviewed
CVE-2025-31214
was published
May 13, 2025
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could...
High
Unreviewed
CVE-2025-20122
was published
May 7, 2025
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in...
Low
Unreviewed
CVE-2024-50565
was published
Apr 8, 2025
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2...
Moderate
Unreviewed
CVE-2023-38272
was published
Mar 27, 2025
The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which...
High
Unreviewed
CVE-2025-2190
was published
Mar 11, 2025
2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle...
High
Unreviewed
CVE-2024-47258
was published
Feb 6, 2025
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to...
High
Unreviewed
CVE-2024-36553
was published
Feb 6, 2025
Identity verification vulnerability in the ParamWatcher module
Impact: Successful exploitation of...
Moderate
Unreviewed
CVE-2024-12602
was published
Feb 6, 2025
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an...
Moderate
Unreviewed
CVE-2024-27263
was published
Jan 28, 2025
The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and...
Moderate
Unreviewed
CVE-2024-27267
was published
Aug 14, 2024
ntlk unsafe deserialization vulnerability
High
CVE-2024-39705
was published
for
nltk
(pip)
Jun 28, 2024
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG...
High
Unreviewed
CVE-2024-32049
was published
May 8, 2024
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man...
Critical
Unreviewed
CVE-2019-19755
was published
Apr 30, 2024
easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which...
Moderate
Unreviewed
CVE-2019-19751
was published
Apr 30, 2024
dectalk-tts Uses Unencrypted HTTP Request
High
CVE-2024-31206
was published
for
dectalk-tts
(npm)
Apr 4, 2024
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2023-47742
was published
Mar 3, 2024
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0...
High
Unreviewed
CVE-2023-31004
was published
Feb 3, 2024
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept...
Moderate
Unreviewed
CVE-2023-7008
was published
Dec 23, 2023
Go package github.com/edgelesssys/marblerun CLI commands susceptible to MITM attacks
High
GHSA-j3rq-4xjw-xg63
was published
for
github.com/edgelesssys/marblerun
(Go)
Dec 4, 2023
ProTip!
Advisories are also available from the
GraphQL API