GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
8,321 advisories
Filter by severity
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin
High
CVE-2025-32777
was published
for
volcano.sh/volcano
(Go)
Apr 30, 2025
Homograph attack allows Unicode lookalike characters to bypass validation.
High
CVE-2025-27611
was published
for
base-x
(npm)
Apr 30, 2025
Duplicate Advisory: Keycloak hostname verification
High
GHSA-r934-w73g-v4p8
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 29, 2025
•
withdrawn
Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
High
CVE-2025-46342
was published
for
github.com/kyverno/kyverno
(Go)
Apr 29, 2025
Data exposure via ZeroMQ on multi-node vLLM deployment
High
CVE-2025-30202
was published
for
vllm
(pip)
Apr 29, 2025
YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
High
CVE-2025-46347
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
High
CVE-2025-46349
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
CVE-2025-22235
was published
for
org.springframework.boot:spring-boot
(Maven)
Apr 28, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
High
CVE-2025-3641
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
High
CVE-2025-3642
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows unauthenticated REST API user data exposure
High
CVE-2025-32044
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Steve doesn’t verify a server’s certificate and is susceptible to man-in-the-middle (MitM) attacks
High
CVE-2023-32198
was published
for
github.com/rancher/steve
(Go)
Apr 25, 2025
Rancher users who can create Projects can gain access to arbitrary projects
High
CVE-2024-22031
was published
for
github.com/rancher/rancher
(Go)
Apr 25, 2025
React Router allows pre-render data spoofing on React-Router framework mode
High
CVE-2025-43865
was published
for
react-router
(npm)
Apr 24, 2025
React Router allows a DoS via cache poisoning by forcing SPA mode
High
CVE-2025-43864
was published
for
react-router
(npm)
Apr 24, 2025
tRPC 11 WebSocket DoS Vulnerability
High
CVE-2025-43855
was published
for
@trpc/server
(npm)
Apr 24, 2025
Apache HttpClient disables domain checks
High
CVE-2025-27820
was published
for
org.apache.httpcomponents.client5:httpclient5
(Maven)
Apr 24, 2025
PostHog Plugin Server SQL Injection Vulnerability
High
CVE-2025-1520
was published
for
@posthog/plugin-server
(npm)
Apr 23, 2025
org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
High
CVE-2025-32968
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 23, 2025
Infinite loop condition in Amazon.IonDotnet
High
CVE-2025-3857
was published
for
Amazon.IonDotnet
(NuGet)
Apr 21, 2025
Traefik has a possible vulnerability with the path matchers
High
CVE-2025-32431
was published
for
github.com/traefik/traefik
(Go)
Apr 21, 2025
GoBGP panics due to a zero value for softwareVersionLen
High
CVE-2025-43971
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
High
GHSA-22fp-mf44-f2mq
was published
for
youtube-dl
(pip)
Apr 18, 2025
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
High
GHSA-3wqc-mwfx-672p
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
ses's global contour bindings leak into Compartment lexical scope
High
CVE-2025-32792
was published
for
ses
(npm)
Apr 18, 2025
ProTip!
Advisories are also available from the
GraphQL API