GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
127 advisories
Filter by severity
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client
High
CVE-2025-66035
was published
for
@angular/common
(npm)
Nov 26, 2025
The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
Moderate
Unreviewed
CVE-2025-12536
was published
Nov 13, 2025
Files or Directories Accessible to External Parties, Exposure of Private Personal Information to...
High
Unreviewed
CVE-2025-11959
was published
Nov 11, 2025
IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX...
Moderate
Unreviewed
CVE-2025-36131
was published
Nov 7, 2025
HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application...
Moderate
Unreviewed
CVE-2025-52602
was published
Nov 5, 2025
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in...
High
Unreviewed
CVE-2025-43500
was published
Nov 4, 2025
The issue was addressed by adding additional logic. This issue is fixed in watchOS 26.1, iOS 26.1...
High
Unreviewed
CVE-2025-43496
was published
Nov 4, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2025-43469
was published
Nov 4, 2025
This issue was addressed by restricting options offered on a locked device. This issue is fixed...
High
Unreviewed
CVE-2025-43452
was published
Nov 4, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
High
Unreviewed
CVE-2025-43409
was published
Nov 4, 2025
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.1 and...
High
Unreviewed
CVE-2025-43439
was published
Nov 4, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
High
Unreviewed
CVE-2025-43405
was published
Nov 4, 2025
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
High
Unreviewed
CVE-2025-43399
was published
Nov 4, 2025
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.1...
High
Unreviewed
CVE-2025-43389
was published
Nov 4, 2025
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre...
Moderate
Unreviewed
CVE-2025-35981
was published
Oct 23, 2025
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 has a Global...
Moderate
Unreviewed
CVE-2025-62644
was published
Oct 17, 2025
An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in...
Moderate
Unreviewed
CVE-2025-53950
was published
Oct 16, 2025
In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire...
Low
Unreviewed
CVE-2025-5009
was published
Oct 8, 2025
Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing...
Moderate
Unreviewed
CVE-2025-10859
was published
Sep 30, 2025
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Low
Unreviewed
CVE-2025-43357
was published
Sep 16, 2025
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43310
was published
Sep 16, 2025
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Moderate
Unreviewed
CVE-2025-43279
was published
Sep 16, 2025
A privacy issue was addressed with improved private data redaction for log entries. This issue is...
Low
Unreviewed
CVE-2025-43301
was published
Sep 16, 2025
Presta Shop vulnerable to email enumeration
Moderate
CVE-2025-51586
was published
for
prestashop/prestashop
(Composer)
Sep 4, 2025
A low-privileged remote attacker can obtain the username of another registered Sunny Portal user...
Moderate
Unreviewed
CVE-2025-41685
was published
Aug 19, 2025
ProTip!
Advisories are also available from the
GraphQL API