GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,875
Maven
5,000+
npm
4,501
NuGet
780
pip
4,254
Pub
12
RubyGems
975
Rust
1,099
Swift
49
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
287,311 advisories
Filter by severity
Improper Authentication vulnerability in Delinea Inc. Secret Server On-Prem (RPC Password...
Moderate
Unreviewed
CVE-2025-12810
was published
Jan 27, 2026
Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110...
Unknown
Unreviewed
CVE-2026-1504
was published
Jan 27, 2026
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized...
High
Unreviewed
CVE-2026-24881
was published
Jan 27, 2026
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success...
Low
Unreviewed
CVE-2026-24883
was published
Jan 27, 2026
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file...
Critical
Unreviewed
CVE-2025-14988
was published
Jan 27, 2026
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the...
High
Unreviewed
CVE-2026-24882
was published
Jan 27, 2026
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability...
Critical
Unreviewed
CVE-2026-24858
was published
Jan 27, 2026
An Authentication Bypass Using an
Alternate Path or Channel vulnerability in Juniper Networks...
Critical
Unreviewed
CVE-2025-21589
was published
Jan 27, 2026
The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions...
Moderate
Unreviewed
CVE-2026-0746
was published
Jan 27, 2026
Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability...
Moderate
Unreviewed
CVE-2020-36978
was published
Jan 27, 2026
EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows...
High
Unreviewed
CVE-2020-36975
was published
Jan 27, 2026
SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its Windows service...
High
Unreviewed
CVE-2020-36980
was published
Jan 27, 2026
Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service...
High
Unreviewed
CVE-2020-36981
was published
Jan 27, 2026
Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local...
High
Unreviewed
CVE-2020-36983
was published
Jan 27, 2026
Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its...
High
Unreviewed
CVE-2020-36979
was published
Jan 27, 2026
Wondershare Driver Install Service contains an unquoted service path vulnerability in the...
High
Unreviewed
CVE-2020-36977
was published
Jan 27, 2026
Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the...
High
Unreviewed
CVE-2020-36982
was published
Jan 27, 2026
Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its...
High
Unreviewed
CVE-2020-36976
was published
Jan 27, 2026
Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows...
High
Unreviewed
CVE-2020-36974
was published
Jan 27, 2026
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
Unknown
Unreviewed
CVE-2025-69559
was published
Jan 27, 2026
NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful...
High
Unreviewed
CVE-2025-33234
was published
Jan 27, 2026
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance...
Critical
Unreviewed
CVE-2026-1472
was published
Jan 27, 2026
The Tapo C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests...
High
Unreviewed
CVE-2026-0918
was published
Jan 27, 2026
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance...
Critical
Unreviewed
CVE-2026-1477
was published
Jan 27, 2026
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance...
Critical
Unreviewed
CVE-2026-1473
was published
Jan 27, 2026
ProTip!
Advisories are also available from the
GraphQL API