GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
8,321 advisories
Filter by severity
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting
High
CVE-2025-47885
was published
for
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
(Maven)
May 14, 2025
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
High
CVE-2025-47889
was published
for
org.jenkins-ci.plugins:wso2id-oauth
(Maven)
May 14, 2025
Cosmos EVM Allows Partial Precompile State Writes
High
GHSA-mjfq-3qr2-6g84
was published
for
github.com/cosmos/evm
(Go)
May 14, 2025
Yggdrasil Vulnerable to Local Privilege Escalation
High
CVE-2025-3931
was published
for
github.com/redhatinsights/yggdrasil
(Go)
May 14, 2025
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
High
CVE-2025-26646
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
May 13, 2025
OXID eShop May Display User Information
High
CVE-2024-56526
was published
for
oxid-esales/oxideshop-ce
(Composer)
May 13, 2025
LlamaIndex Vulnerable to Denial of Service (DoS)
High
CVE-2025-1752
was published
for
llama-index
(pip)
May 10, 2025
code-server's session cookie can be extracted by having user visit specially crafted proxy URL
High
CVE-2025-47269
was published
for
code-server
(npm)
May 9, 2025
Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
High
CVE-2025-1948
was published
for
org.eclipse.jetty.http2:jetty-http2-common
(Maven)
May 8, 2025
**UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
High
CVE-2024-13009
was published
for
org.eclipse.jetty:jetty-server
(Maven)
May 8, 2025
Rack has an Unbounded-Parameter DoS in Rack::QueryParser
High
CVE-2025-46727
was published
for
rack
(RubyGems)
May 8, 2025
Graylog Allows Session Takeover via Insufficient HTML Sanitization
High
CVE-2025-46827
was published
for
org.graylog2:graylog2-server
(Maven)
May 7, 2025
Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
High
GHSA-q9q2-3ppx-mwqf
was published
for
org.graylog2:graylog2-server
(Maven)
May 7, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Attribute Smuggling
High
CVE-2025-46573
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
High
CVE-2025-30165
was published
for
vllm
(pip)
May 6, 2025
Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
High
CVE-2025-46762
was published
for
org.apache.parquet:parquet-avro
(Maven)
May 6, 2025
Langroid Allows XXE Injection via XMLToolMessage
High
CVE-2025-46726
was published
for
langroid
(pip)
May 5, 2025
OpenVM allows the byte decomposition of pc in AUIPC chip to overflow
High
CVE-2025-46723
was published
for
openvm
(Rust)
May 5, 2025
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
High
CVE-2025-46731
was published
for
craftcms/cms
(Composer)
May 5, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Keycloak hostname verification
High
CVE-2025-3501
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
Any user with view access to the XWiki space can change the authenticator
High
CVE-2025-46557
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-ui
(Maven)
Apr 30, 2025
ProTip!
Advisories are also available from the
GraphQL API