GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,888 advisories
Filter by severity
The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure...
Moderate
Unreviewed
CVE-2025-10750
was published
Oct 18, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia...
Moderate
Unreviewed
CVE-2025-62669
was published
Oct 18, 2025
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation...
Low
Unreviewed
CVE-2025-23073
was published
Jan 14, 2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
Moderate
CVE-2025-53092
was published
for
@strapi/core
(npm)
Oct 16, 2025
A compromised web process using malicious IPC messages could have caused the privileged browser...
Critical
Unreviewed
CVE-2025-11710
was published
Oct 14, 2025
When switching between Android apps using the card carousel Firefox shows a black screen as its...
Critical
Unreviewed
CVE-2025-11717
was published
Oct 14, 2025
Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations...
High
Unreviewed
CVE-2024-8055
was published
Mar 20, 2025
In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows...
High
Unreviewed
CVE-2024-6842
was published
Mar 20, 2025
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack...
High
Unreviewed
CVE-2024-7010
was published
Oct 29, 2024
A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for...
Moderate
Unreviewed
CVE-2024-0245
was published
Mar 20, 2025
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3502
was published
Nov 14, 2024
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
The External Login plugin for WordPress is vulnerable to sensitive information exposure in all...
Moderate
Unreviewed
CVE-2025-11196
was published
Oct 15, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual...
Moderate
Unreviewed
CVE-2025-59260
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized...
Low
Unreviewed
CVE-2025-59284
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an...
Low
Unreviewed
CVE-2025-59294
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an...
Moderate
Unreviewed
CVE-2025-59214
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an...
Moderate
Unreviewed
CVE-2025-58739
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core...
Moderate
Unreviewed
CVE-2025-59211
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Moderate
Unreviewed
CVE-2025-59186
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an...
Moderate
Unreviewed
CVE-2025-59188
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows High Availability Services...
Moderate
Unreviewed
CVE-2025-59184
was published
Oct 14, 2025
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized...
Moderate
Unreviewed
CVE-2025-55699
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API