GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
8,339 advisories
Filter by severity
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
High
CVE-2025-48075
was published
for
github.com/gofiber/fiber/v2
(Go)
May 22, 2025
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
High
CVE-2025-4123
was published
for
github.com/grafana/grafana
(Go)
May 22, 2025
The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource Location
High
CVE-2025-48201
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object Reference
High
CVE-2025-48205
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
containerd allows host filesystem access on pull
High
CVE-2025-47290
was published
for
github.com/containerd/containerd/v2
(Go)
May 21, 2025
The TYPO3 CMS Backend has Broken Authentication in Backend MFA
High
CVE-2025-47941
was published
for
typo3/cms-backend
(Composer)
May 20, 2025
TYPO3 Allows Privilege Escalation to System Maintainer
High
CVE-2025-47940
was published
for
typo3/cms-core
(Composer)
May 20, 2025
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
High
CVE-2025-46725
was published
for
langroid
(pip)
May 20, 2025
Multer vulnerable to Denial of Service from maliciously crafted requests
High
CVE-2025-47944
was published
for
multer
(npm)
May 19, 2025
Multer vulnerable to Denial of Service via memory leaks from unclosed streams
High
CVE-2025-47935
was published
for
multer
(npm)
May 19, 2025
OpenPGP.js's message signature verification can be spoofed
High
CVE-2025-47934
was published
for
openpgp
(npm)
May 19, 2025
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
High
CVE-2025-47273
was published
for
setuptools
(pip)
May 19, 2025
Tornado vulnerable to excessive logging caused by malformed multipart form data
High
CVE-2025-47287
was published
for
tornado
(pip)
May 16, 2025
Ollama Server Vulnerable to Denial of Service (DoS) Attack
High
CVE-2025-1975
was published
for
github.com/ollama/ollama
(Go)
May 16, 2025
macroquad vulnerable to multiple soundness issues
High
GHSA-gg76-hg3v-5q6c
was published
for
macroquad
(Rust)
May 15, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
CVE-2025-47783
was published
for
label-studio
(pip)
May 15, 2025
Reflex vulnerable to private state fields modification
High
CVE-2025-47425
was published
for
reflex
(pip)
May 15, 2025
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
High
CVE-2025-47782
was published
for
motioneye
(pip)
May 15, 2025
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting
High
CVE-2025-47885
was published
for
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
(Maven)
May 14, 2025
Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
High
CVE-2025-47889
was published
for
org.jenkins-ci.plugins:wso2id-oauth
(Maven)
May 14, 2025
Cosmos EVM Allows Partial Precompile State Writes
High
GHSA-mjfq-3qr2-6g84
was published
for
github.com/cosmos/evm
(Go)
May 14, 2025
Yggdrasil Vulnerable to Local Privilege Escalation
High
CVE-2025-3931
was published
for
github.com/redhatinsights/yggdrasil
(Go)
May 14, 2025
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
High
CVE-2025-26646
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API