GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
293,354 advisories
Filter by severity
Liferay Portal Uses Default Password
Moderate
CVE-2025-43799
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 15, 2025
Liferay DXP Missing Critical Step in Authentication
Low
CVE-2025-43798
was published
for
com.liferay:com.liferay.multi.factor.authentication.timebased.otp.web
(Maven)
Sep 15, 2025
Liferay Portal Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2025-43800
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Sep 15, 2025
WebSSH Cross-site Scripting vulnerability
Low
CVE-2025-7885
was published
for
webssh
(pip)
Jul 20, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59331
was published
for
is-arrayish
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59330
was published
for
error-ex
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59162
was published
for
color-convert
(npm)
Sep 15, 2025
Liferay Portal vulnerable to Cross-site Scripting
Moderate
CVE-2025-43791
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.field.type
(Maven)
Sep 15, 2025
Apache Fory Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-59328
was published
for
org.apache.fory:fory-core
(Maven)
Sep 15, 2025
Liferay Portal has External Control of System or Configuration Settings
Low
CVE-2025-43792
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59145
was published
for
color-name
(npm)
Sep 15, 2025
Liferay Portal has Improper Validation of Specified Quantity in Input
Moderate
CVE-2025-43793
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59144
was published
for
debug
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59143
was published
for
color
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59142
was published
for
color-string
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59141
was published
for
simple-swizzle
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59140
was published
for
backslash
(npm)
Sep 15, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-8396
was published
for
go.temporal.io/server
(Go)
Sep 15, 2025
mcp-kubernetes-server has an OS Command Injection vulnerability
Low
CVE-2025-59377
was published
for
mcp-kubernetes-server
(pip)
Sep 15, 2025
mcp-kubernetes-server has a Command Injection vulnerability
Low
CVE-2025-59376
was published
for
mcp-kubernetes-server
(pip)
Sep 15, 2025
Xuxueli XXL-SSO Cross-site Scripting vulnerability
Low
CVE-2025-6700
was published
for
com.xuxueli:xxl-sso
(Maven)
Jun 26, 2025
A vulnerability was determined in neurobin shc up to 4.0.3. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-9174
was published
Aug 20, 2025
The rfpiped service on TCP port 555 in Ceragon Networks / Siklu Communication EtherHaul series ...
Moderate
Unreviewed
CVE-2025-57176
was published
Sep 15, 2025
Cross Site Scripting (xss) vulnerability in ServitiumCRM 2.10 allowing attackers to execute...
Moderate
Unreviewed
CVE-2025-56252
was published
Sep 15, 2025
Improper input validation in Windows Common Log File System Driver allows an authorized attacker...
High
Unreviewed
CVE-2025-32706
was published
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API