GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
35 advisories
Filter by severity
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an...
High
Unreviewed
CVE-2026-21514
was published
Feb 10, 2026
Cube Core is vulnerable to privilege escalation via a specially crafted request
High
CVE-2026-25958
was published
for
@cubejs-backend/server-core
(npm)
Feb 10, 2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized...
High
Unreviewed
CVE-2026-21509
was published
Jan 26, 2026
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized...
High
Unreviewed
CVE-2026-20849
was published
Jan 13, 2026
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF)...
Moderate
Unreviewed
CVE-2025-65328
was published
Jan 5, 2026
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code...
Critical
Unreviewed
CVE-2025-12488
was published
Nov 6, 2025
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code...
Critical
Unreviewed
CVE-2025-12487
was published
Nov 6, 2025
The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all...
Moderate
Unreviewed
CVE-2025-11271
was published
Nov 6, 2025
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS...
High
Unreviewed
CVE-2025-53717
was published
Oct 14, 2025
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
High
CVE-2025-59152
was published
for
litestar
(pip)
Oct 6, 2025
github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Moderate
CVE-2025-47909
was published
for
github.com/gorilla/csrf
(Go)
Aug 29, 2025
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate...
Critical
Unreviewed
CVE-2025-53882
was published
Jul 23, 2025
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21...
High
Unreviewed
CVE-2024-13974
was published
Jul 21, 2025
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices...
High
Unreviewed
CVE-2025-0117
was published
Mar 12, 2025
Duplicate Advisory: Picklescan Allows Remote Code Execution via Malicious Pickle File Bypassing Static Analysis
Moderate
GHSA-hw34-rqc5-h2gm
was published
for
picklescan
(pip)
Mar 3, 2025
•
withdrawn
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the...
Critical
Unreviewed
CVE-2025-1126
was published
Feb 11, 2025
By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals...
Moderate
Unreviewed
CVE-2024-9310
was published
Jan 22, 2025
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to...
Moderate
Unreviewed
CVE-2024-45654
was published
Jan 19, 2025
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient
Verification of Data...
Moderate
Unreviewed
CVE-2024-47254
was published
Nov 5, 2024
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in...
Critical
Unreviewed
CVE-2024-51561
was published
Nov 4, 2024
Sinatra vulnerable to Reliance on Untrusted Inputs in a Security Decision
Moderate
CVE-2024-21510
was published
for
sinatra
(RubyGems)
Nov 1, 2024
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533...
High
Unreviewed
CVE-2024-7005
was published
Aug 6, 2024
Rancher Privilege escalation vulnerability via malicious "Connection" header
High
CVE-2021-31999
was published
for
github.com/rancher/rancher
(Go)
Apr 24, 2024
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to...
Moderate
Unreviewed
CVE-2023-46686
was published
Dec 19, 2023
ProTip!
Advisories are also available from the
GraphQL API