GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,542 advisories
Filter by severity
Kubernetes kube-apiserver Vulnerable to Race Condition
Low
CVE-2024-7598
was published
for
k8s.io/kubernetes/cmd/kube-apiserver
(Go)
Mar 20, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Low
CVE-2024-47552
was published
for
org.apache.seata:seata-config-core
(Maven)
Mar 20, 2025
Apache Seata Vulnerable to Data Amplification
Low
CVE-2024-54016
was published
for
org.apache.seata:seata-parent
(Maven)
Mar 20, 2025
Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
Low
CVE-2025-30197
was published
for
io.jenkins.plugins:zohoqengine
(Maven)
Mar 19, 2025
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Low
CVE-2025-1398
was published
for
mattermost-desktop
(npm)
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
CVE-2025-27512
was published
for
zincati
(Rust)
Mar 17, 2025
Snowflake JDBC Driver client-side encryption key in DEBUG logs
Low
CVE-2025-27496
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Mar 13, 2025
MODX allows cross-site scripting (XSS) via an SVG file
Low
CVE-2025-28010
was published
for
modx/revolution
(Composer)
Mar 13, 2025
Microweber vulnerable to XSS attack due to insure `group` component in its Settings handler
Low
CVE-2025-2214
was published
for
microweber/microweber
(Composer)
Mar 12, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
CVE-2025-27221
was published
for
uri
(RubyGems)
Mar 3, 2025
Magento LTS vulnerable to stored XSS in theme config fields
Low
CVE-2025-27400
was published
for
openmage/magento-lts
(Composer)
Mar 3, 2025
seajs Cross-site Scripting vulnerability
Low
CVE-2024-51091
was published
for
seajs
(npm)
Mar 3, 2025
Apache Ranger Improper Neutralization of Formula Elements vulnerability
Low
CVE-2024-55532
was published
for
org.apache.ranger:security-admin-web
(Maven)
Mar 3, 2025
Flask-AppBuilder Observable Response Discrepancy
Low
CVE-2025-24023
was published
for
flask-appbuilder
(pip)
Mar 3, 2025
MongoDB Shell may be susceptible to control character Injection via shell output
Low
CVE-2025-1693
was published
for
mongosh
(npm)
Feb 27, 2025
copyparty renders unsanitized filenames as HTML when user uploads empty files
Low
CVE-2025-27145
was published
for
copyparty
(pip)
Feb 26, 2025
Matrix IRC Bridge allows IRC command injection to own puppeted user
Low
CVE-2025-27146
was published
for
matrix-appservice-irc
(npm)
Feb 25, 2025
Moodle has an IDOR in badges allows disabling of arbitrary badges
Low
CVE-2025-26531
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle allows teachers to evade trusttext config when restoring glossary entries
Low
CVE-2025-26532
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a stored XSS in ddimageortext question type
Low
CVE-2025-26528
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Mattermost fails to invalidate all active sessions when converting a user to a bot
Low
CVE-2025-1412
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
tarteaucitron Cross-site Scripting (XSS)
Low
CVE-2025-1467
was published
for
tarteaucitronjs
(npm)
Feb 23, 2025
Leantime allows Cross-Site Scripting (XSS)
Low
GHSA-f679-254h-qhvj
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
ProTip!
Advisories are also available from the
GraphQL API