GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,845
Erlang
36
GitHub Actions
33
Go
2,465
Maven
5,000+
npm
4,089
NuGet
733
pip
3,907
Pub
12
RubyGems
944
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
267,188 advisories
Filter by severity
SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute...
Unknown
Unreviewed
CVE-2025-50972
was published
Aug 27, 2025
A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function...
Moderate
Unreviewed
CVE-2025-9531
was published
Aug 27, 2025
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A...
High
Unreviewed
CVE-2025-43882
was published
Aug 27, 2025
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument...
High
Unreviewed
CVE-2025-43730
was published
Aug 27, 2025
A flaw has been found in Portabilis i-Educar up to 2.10. This impacts an unknown function of the...
Moderate
Unreviewed
CVE-2025-9532
was published
Aug 27, 2025
A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the...
High
Unreviewed
CVE-2025-9525
was published
Aug 27, 2025
Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure...
Critical
Unreviewed
CVE-2025-43728
was published
Aug 27, 2025
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template...
Critical
Unreviewed
CVE-2025-52122
was published
Aug 27, 2025
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-9528
was published
Aug 27, 2025
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element...
Moderate
Unreviewed
CVE-2025-9529
was published
Aug 27, 2025
A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the...
High
Unreviewed
CVE-2025-9527
was published
Aug 27, 2025
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for...
High
Unreviewed
CVE-2025-43729
was published
Aug 27, 2025
Client-side password validation (CWE-602) in lumasoft fotoShare Cloud 2025-03-13 allowing...
Moderate
Unreviewed
CVE-2025-56694
was published
Aug 27, 2025
A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the...
High
Unreviewed
CVE-2025-9526
was published
Aug 27, 2025
diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2025-50986
was published
Aug 27, 2025
diskover-web v2.3.0 Community Edition is vulnerable to multiple reflected cross-site scripting ...
Unknown
Unreviewed
CVE-2025-50985
was published
Aug 27, 2025
OPNsense 25.1 contains an authenticated command injection vulnerability in its Bridge Interface...
High
Unreviewed
CVE-2025-50989
was published
Aug 27, 2025
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-9533
was published
Aug 27, 2025
The RunCommand function accepts any parameter, which is then passed for execution in the shell....
Critical
Unreviewed
CVE-2025-30056
was published
Aug 27, 2025
In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability...
Moderate
Unreviewed
CVE-2025-30061
was published
Aug 27, 2025
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command...
Critical
Unreviewed
CVE-2025-30057
was published
Aug 27, 2025
In the PrepareCDExportJSON.pl service, the "getPerfServiceIds" function is vulnerable to SQL...
Moderate
Unreviewed
CVE-2025-30059
was published
Aug 27, 2025
In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL...
Moderate
Unreviewed
CVE-2025-30058
was published
Aug 27, 2025
A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function...
High
Unreviewed
CVE-2025-9523
was published
Aug 27, 2025
An insufficiently secured internal function allows session generation for arbitrary users. The...
High
Unreviewed
CVE-2025-30064
was published
Aug 27, 2025
ProTip!
Advisories are also available from the
GraphQL API