GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,123 advisories
Filter by severity
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
create-choo-app3 is vulnerable to Command Injection via the devInstall function
High
CVE-2022-25855
was published
for
create-choo-app3
(npm)
Feb 6, 2023
semver-tags is vulnerable to Command Injection via the getGitTagsRemote function
High
CVE-2022-25853
was published
for
semver-tags
(npm)
Feb 6, 2023
nossrf Server-Side Request Forgery (SSRF)
High
CVE-2025-2691
was published
for
nossrf
(npm)
Mar 23, 2025
Vite bypasses server.fs.deny when using ?raw??
Moderate
CVE-2025-30208
was published
for
vite
(npm)
Mar 25, 2025
GetmeUK ContentTools Cross-Site Scripting (XSS)
Moderate
CVE-2025-2699
was published
for
ContentTools
(npm)
Mar 24, 2025
Duplicate Advisory: Code injection in Directus
Moderate
GHSA-qf6h-p3mr-vmh5
was published
for
directus
(npm)
Aug 15, 2024
•
withdrawn
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High
CVE-2024-12534
was published
for
open-webui
(npm)
Mar 20, 2025
AWS Amplify CLI has incorrect trust policy management
Critical
CVE-2024-28056
was published
for
@aws-amplify/cli
(npm)
Apr 15, 2024
Nuxt allows DOS via cache poisoning with payload rendering response
High
CVE-2025-27415
was published
for
nuxt
(npm)
Mar 19, 2025
Prototype Pollution Vulnerability in parse-git-config
High
CVE-2025-25975
was published
for
parse-git-config
(npm)
Mar 12, 2025
Fast-JWT Improperly Validates iss Claims
Moderate
CVE-2025-30144
was published
for
fast-jwt
(npm)
Mar 19, 2025
Directus has an insecure object reference via PATH presets
Moderate
CVE-2024-6534
was published
for
directus
(npm)
Aug 27, 2024
Duplicate Advisory: Improper access control in Directus
Moderate
GHSA-q83v-hq3j-4pq3
was published
for
directus
(npm)
Aug 15, 2024
•
withdrawn
@zag-js/core prototype pollution
High
CVE-2024-57079
was published
for
@zag-js/core
(npm)
Feb 6, 2025
jsPDF Bypass Regular Expression Denial of Service (ReDoS)
High
CVE-2025-29907
was published
for
jspdf
(npm)
Mar 18, 2025
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Low
CVE-2025-1398
was published
for
mattermost-desktop
(npm)
Mar 17, 2025
canvg Prototype Pollution vulnerability
High
CVE-2025-25977
was published
for
canvg
(npm)
Mar 10, 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
Critical
CVE-2025-29775
was published
for
xml-crypto
(npm)
Mar 14, 2025
xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References
Critical
CVE-2025-29774
was published
for
xml-crypto
(npm)
Mar 14, 2025
JS Html Sanitizer allows XSS when used with contentEditable
Moderate
CVE-2025-29771
was published
for
@jitbit/htmlsanitizer
(npm)
Mar 14, 2025
ProTip!
Advisories are also available from the
GraphQL API