GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
149 advisories
Filter by severity
CNCF K3s Kubernetes kubelet configuration exposes credentials
Moderate
CVE-2025-46599
was published
for
github.com/k3s-io/k3s
(Go)
Apr 25, 2025
Insecure default settings have been found in recorder products provided by Yokogawa Electric...
Critical
Unreviewed
CVE-2025-1863
was published
Apr 18, 2025
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces
High
Unreviewed
CVE-2025-43015
was published
Apr 17, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Moderate
Unreviewed
CVE-2025-2442
was published
Apr 9, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Moderate
Unreviewed
CVE-2025-2441
was published
Apr 9, 2025
Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an...
Low
Unreviewed
CVE-2025-27443
was published
Apr 8, 2025
Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Initialization of a Resource...
Moderate
Unreviewed
CVE-2025-29985
was published
Apr 8, 2025
Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have...
Moderate
Unreviewed
CVE-2025-27809
was published
Mar 25, 2025
An unauthenticated remote attacker can gain limited information of the PLC network but the user...
Moderate
Unreviewed
CVE-2024-41975
was published
Mar 18, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Critical
Unreviewed
CVE-2025-1960
was published
Mar 12, 2025
A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects...
Moderate
Unreviewed
CVE-2025-2129
was published
Mar 9, 2025
Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers...
Moderate
Unreviewed
CVE-2024-48122
was published
Jan 15, 2025
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g.,...
Low
Unreviewed
CVE-2024-56433
was published
Dec 26, 2024
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value,...
Moderate
Unreviewed
CVE-2020-11917
was published
Nov 7, 2024
Filament has exported files stored in default (`public`) filesystem if not reconfigured
Low
CVE-2024-51758
was published
for
filament/actions
(Composer)
Nov 7, 2024
Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with...
High
Unreviewed
CVE-2019-25219
was published
Oct 29, 2024
Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user...
Moderate
Unreviewed
CVE-2024-9949
was published
Oct 23, 2024
HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused...
Moderate
Unreviewed
CVE-2024-30124
was published
Oct 23, 2024
Insecure Default Initialization of Resource vulnerability in Apache Solr
High
CVE-2024-45217
was published
for
org.apache.solr:solr
(Maven)
Oct 16, 2024
Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote...
High
Unreviewed
CVE-2024-47295
was published
Oct 1, 2024
A condition exists in FlashArray Purity whereby a local account intended for initial array...
Critical
Unreviewed
CVE-2024-0001
was published
Sep 23, 2024
there is a possible arbitrary read due to an insecure default value. This could lead to local...
Moderate
Unreviewed
CVE-2024-44096
was published
Sep 13, 2024
Firefox normally asks for confirmation before asking the operating system to find an application...
High
Unreviewed
CVE-2024-8383
was published
Sep 3, 2024
In onForegroundServiceButtonClicked of FooterActionsViewModel.kt, there is a possible way to...
High
Unreviewed
CVE-2024-34734
was published
Aug 16, 2024
ProTip!
Advisories are also available from the
GraphQL API