GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,123 advisories
Filter by severity
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Low
CVE-2025-46720
was published
for
@keystone-6/core
(npm)
May 5, 2025
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
Vite's server.fs.deny bypassed with /. for files under project root
Moderate
CVE-2025-46565
was published
for
vite
(npm)
Apr 30, 2025
@cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
CVE-2025-4144
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
GHSA-vh4h-fvqf-q9wv
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Duplicate Advisory: @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
GHSA-7cp4-jw97-3rc2
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Homograph attack allows Unicode lookalike characters to bypass validation.
High
CVE-2025-27611
was published
for
base-x
(npm)
Apr 30, 2025
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
Auth0 NextJS SDK v4 Missing Session Invalidation
Moderate
CVE-2025-46344
was published
for
@auth0/nextjs-auth0
(npm)
Apr 29, 2025
AngularJS improperly sanitizes SVG elements
Low
CVE-2025-0716
was published
for
angular
(npm)
Apr 29, 2025
GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-733v-p3h5-qpq7
was published
for
@escape.tech/graphql-armor-cost-limit
(npm)
Apr 25, 2025
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Moderate
GHSA-wfm2-rq5g-f8v5
was published
for
@account-kit/smart-contracts
(npm)
Apr 29, 2025
n8n Vulnerable to Stored XSS through Attachments View Endpoint
Moderate
CVE-2025-46343
was published
for
n8n
(npm)
Apr 28, 2025
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46328
was published
for
snowflake-sdk
(npm)
Apr 28, 2025
http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
Moderate
CVE-2025-32997
was published
for
http-proxy-middleware
(npm)
Apr 15, 2025
http-proxy-middleware can call writeBody twice because "else if" is not used
Moderate
CVE-2025-32996
was published
for
http-proxy-middleware
(npm)
Apr 15, 2025
Pug allows JavaScript code execution if an application accepts untrusted input
Moderate
CVE-2024-36361
was published
for
pug
(npm)
May 24, 2024
React Router allows pre-render data spoofing on React-Router framework mode
High
CVE-2025-43865
was published
for
react-router
(npm)
Apr 24, 2025
React Router allows a DoS via cache poisoning by forcing SPA mode
High
CVE-2025-43864
was published
for
react-router
(npm)
Apr 24, 2025
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2024-4367
was published
for
pdfjs-dist
(npm)
May 7, 2024
tRPC 11 WebSocket DoS Vulnerability
High
CVE-2025-43855
was published
for
@trpc/server
(npm)
Apr 24, 2025
ProTip!
Advisories are also available from the
GraphQL API