GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
50 advisories
Filter by severity
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated...
High
Unreviewed
CVE-2024-30128
was published
Sep 25, 2024
In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a...
High
Unreviewed
CVE-2024-31319
was published
Jul 9, 2024
Mitmweb API Authentication Bypass Using Proxy Server
High
CVE-2025-23217
was published
for
mitmproxy
(pip)
Feb 6, 2025
In setMediaButtonReceiver of MediaSessionRecord.java, there is a possible way to send a pending...
High
Unreviewed
CVE-2023-40111
was published
Feb 16, 2024
code-server's session cookie can be extracted by having user visit specially crafted proxy URL
High
CVE-2025-47269
was published
for
code-server
(npm)
May 9, 2025
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an...
High
Unreviewed
CVE-2019-1841
was published
May 13, 2022
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an...
High
Unreviewed
CVE-2019-3924
was published
May 13, 2022
In markMediaAsFavorite of MediaProvider.java, there is a possible way to bypass the...
High
Unreviewed
CVE-2025-48532
was published
Sep 4, 2025
In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact...
High
Unreviewed
CVE-2025-32346
was published
Sep 4, 2025
In loadDrawableForCookie of ResourcesImpl.java, there is a possible way to access task snapshots...
High
Unreviewed
CVE-2025-26452
was published
Sep 5, 2025
In System UI, there is a possible way to view other users' images due to a confused deputy. This...
High
Unreviewed
CVE-2025-32320
was published
Sep 5, 2025
In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to...
High
Unreviewed
CVE-2025-26454
was published
Sep 4, 2025
In onCommand of ActivityManagerShellCommand.java, there is a possible arbitrary activity launch...
High
Unreviewed
CVE-2025-32324
was published
Sep 4, 2025
In getContextForResourcesEnsuringCorrectCachedApkPaths of RemoteViews.java, there is a possible...
High
Unreviewed
CVE-2025-22441
was published
Sep 4, 2025
In multiple functions of AppRestrictionsFragment.java, there is a possible way to bypass intent...
High
Unreviewed
CVE-2025-32326
was published
Sep 4, 2025
In isSafeIntent of AccountTypePreferenceLoader.java, there is a possible way to bypass an intent...
High
Unreviewed
CVE-2025-32321
was published
Sep 4, 2025
In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for...
High
Unreviewed
CVE-2025-48536
was published
Dec 8, 2025
In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from...
High
Unreviewed
CVE-2025-48586
was published
Dec 8, 2025
In multiple locations, there is a possible way to leak audio files across user profiles due to a...
High
Unreviewed
CVE-2025-22420
was published
Dec 8, 2025
In multiple functions of NotificationStation.java, there is a possible cross-profile information...
High
Unreviewed
CVE-2025-48555
was published
Dec 8, 2025
In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image...
High
Unreviewed
CVE-2025-48628
was published
Dec 8, 2025
Misconfigured Internal Proxy in runtimes-inventory-rhel8-operator Grants Standard Users Full Cluster Administrator Access
High
CVE-2025-11393
was published
for
github.com/RedHatInsights/runtimes-inventory-operator
(Go)
Dec 15, 2025
Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName
High
CVE-2026-24470
was published
for
github.com/zalando/skipper
(Go)
Jan 26, 2026
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a...
High
Unreviewed
CVE-2023-31313
was published
Feb 12, 2026
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
High
GHSA-3v2x-9xcv-2v2v
was published
for
surrealdb
(Rust)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API