GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,722
Erlang
35
GitHub Actions
29
Go
2,306
Maven
5,000+
npm
3,947
NuGet
711
pip
3,727
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
11,214 advisories
Filter by severity
Jenkins DingTalk Plugin Unconditionally Disables SSL/TLS Certificate and Hostname Validation
Moderate
CVE-2025-47888
was published
for
io.jenkins.plugins:dingding-notifications
(Maven)
May 14, 2025
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input...
Critical
Unreviewed
CVE-2025-43559
was published
May 13, 2025
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input...
Critical
Unreviewed
CVE-2025-43560
was published
May 13, 2025
Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and...
High
Unreviewed
CVE-2025-24308
was published
May 13, 2025
Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and...
High
Unreviewed
CVE-2025-21094
was published
May 13, 2025
Improper input validation in the UEFI firmware GenerationSetup module for the Intel(R) Server...
Moderate
Unreviewed
CVE-2025-20009
was published
May 13, 2025
Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before...
High
Unreviewed
CVE-2025-20032
was published
May 13, 2025
Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to...
Moderate
Unreviewed
CVE-2025-20031
was published
May 13, 2025
Improper input validation in the BackupBiosUpdate UEFI firmware SmiVariable driver for the Intel...
Moderate
Unreviewed
CVE-2025-20034
was published
May 13, 2025
Improper input validation in Windows Common Log File System Driver allows an authorized attacker...
High
Unreviewed
CVE-2025-32706
was published
May 13, 2025
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized...
Moderate
Unreviewed
CVE-2025-29968
was published
May 13, 2025
Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service...
Moderate
Unreviewed
CVE-2025-29955
was published
May 13, 2025
A vulnerability has been identified in BACnet ATEC 550-440 (All versions), BACnet ATEC 550-441 ...
High
Unreviewed
CVE-2025-40556
was published
May 13, 2025
A vulnerability has been identified in MS/TP Point Pickup Module (All versions). Affected devices...
High
Unreviewed
CVE-2025-24510
was published
May 13, 2025
The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15...
High
Unreviewed
CVE-2025-31259
was published
May 13, 2025
This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS...
High
Unreviewed
CVE-2025-31240
was published
May 13, 2025
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5,...
Moderate
Unreviewed
CVE-2025-31215
was published
May 13, 2025
The issue was addressed with improved input validation. This issue is fixed in watchOS 11.5, tvOS...
High
Unreviewed
CVE-2025-31217
was published
May 13, 2025
The issue was addressed with improved input sanitization. This issue is fixed in watchOS 11.5,...
Moderate
Unreviewed
CVE-2025-31233
was published
May 13, 2025
The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15...
High
Unreviewed
CVE-2025-30442
was published
May 13, 2025
The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, macOS Sonoma...
High
Unreviewed
CVE-2025-31208
was published
May 13, 2025
An input validation issue was addressed by removing the vulnerable code. This issue is fixed in...
High
Unreviewed
CVE-2025-24274
was published
May 13, 2025
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that...
Critical
Unreviewed
CVE-2025-1087
was published
May 9, 2025
Improper Input Validation vulnerability in Sparx Systems Pro Cloud Server's WebEA model search...
Moderate
Unreviewed
CVE-2025-4376
was published
May 9, 2025
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro...
High
Unreviewed
CVE-2025-4377
was published
May 9, 2025
ProTip!
Advisories are also available from the
GraphQL API