GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,494
Maven
5,000+
npm
4,133
NuGet
735
pip
3,944
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
293,329 advisories
Filter by severity
Flowise has an Arbitrary File Read
Critical
GHSA-99pg-hqvx-r4gf
was published
for
flowise
(npm)
Sep 15, 2025
Flowise has Remote Code Execution vulnerability
Critical
GHSA-3gcm-f6qx-ff7p
was published
for
flowise
(npm)
Sep 15, 2025
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
High
GHSA-hr92-4q35-4j3m
was published
for
flowise
(npm)
Sep 15, 2025
FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
GHSA-7944-7c6r-55vv
was published
for
flowise
(npm)
Sep 15, 2025
wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api...
Unknown
Unreviewed
CVE-2025-49089
was published
Sep 15, 2025
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0...
Moderate
Unreviewed
CVE-2025-43793
was published
Sep 15, 2025
IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another...
Moderate
Unreviewed
CVE-2025-36082
was published
Sep 15, 2025
Teampel 5.1.6 is vulnerable to SQL Injection in /Common/login.aspx.
Unknown
Unreviewed
CVE-2025-57104
was published
Sep 15, 2025
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111,...
Moderate
Unreviewed
CVE-2025-43791
was published
Sep 15, 2025
The rfpiped service on TCP port 555 in Ceragon Networks / Siklu Communication EtherHaul series ...
Unknown
Unreviewed
CVE-2025-57176
was published
Sep 15, 2025
Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and...
Low
Unreviewed
CVE-2025-43792
was published
Sep 15, 2025
Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute...
Unknown
Unreviewed
CVE-2025-56252
was published
Sep 15, 2025
Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2...
Moderate
Unreviewed
CVE-2025-52344
was published
Sep 15, 2025
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4...
Unknown
Unreviewed
CVE-2025-57174
was published
Sep 15, 2025
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was...
Unknown
Unreviewed
CVE-2025-55777
was published
Sep 15, 2025
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories...
High
Unreviewed
CVE-2025-10491
was published
Sep 15, 2025
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing...
High
Unreviewed
CVE-2025-57248
was published
Sep 15, 2025
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that...
High
Unreviewed
CVE-2025-10203
was published
Sep 15, 2025
Open Web Analytics (OWA) before 1.8.1 allows SQL injection.
Moderate
Unreviewed
CVE-2025-59397
was published
Sep 15, 2025
A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src...
Moderate
Unreviewed
CVE-2025-10471
was published
Sep 15, 2025
A vulnerability in Apache Fory allows a remote attacker to cause a Denial of Service (DoS). The...
Moderate
Unreviewed
CVE-2025-59328
was published
Sep 15, 2025
FUSE-Rust: Uninitalized memory read and leak caused by fuser crate
High
GHSA-cvmj-47v9-35m9
was published
for
fuser
(Rust)
Sep 15, 2025
Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter
Moderate
CVE-2025-58177
was published
for
n8n
(npm)
Sep 15, 2025
Envoy: Race condition in Dynamic Forward Proxy leads to use-after-free and segmentation faults
High
CVE-2025-54588
was published
for
github.com/envoyproxy/envoy
(Go)
Sep 15, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API