GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,560 advisories
Filter by severity
n8n Vulnerable to Denial of Service via Malformed Binary Data Requests
Moderate
CVE-2025-49595
was published
for
n8n
(npm)
Jul 3, 2025
HashiCorp Vagrant has code injection vulnerability through default synced folders
Moderate
CVE-2025-34075
was published
for
vagrant
(RubyGems)
Jul 2, 2025
Microweber CMS API has authenticated local file inclusion vulnerability
Moderate
CVE-2025-34076
was published
for
microweber/microweber
(Composer)
Jul 2, 2025
ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions
Moderate
CVE-2025-53359
was published
for
ethereum
(Rust)
Jul 2, 2025
junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener
Moderate
CVE-2025-53103
was published
for
org.junit.platform:junit-platform-reporting
(Maven)
Jul 1, 2025
juju/utils leaks private key in certs
Moderate
CVE-2025-6224
was published
for
github.com/juju/utils/v4/cert
(Go)
Jul 1, 2025
Electron vulnerable to Heap Buffer Overflow in NativeImage
Moderate
CVE-2024-46993
was published
for
electron
(npm)
Jun 30, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-47871
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 30, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-46702
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 30, 2025
File Browser vulnerable to insecure password handling
Moderate
CVE-2025-52997
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
File Browser allows sensitive data to be transferred in URL
Moderate
CVE-2025-52901
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
akka-cluster-metrics uses Java serialization for cluster metrics
Moderate
CVE-2025-53393
was published
for
com.typesafe.akka:akka-cluster-metrics_2.13
(Maven)
Jun 29, 2025
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
Moderate
CVE-2025-6773
was published
for
lightrag-hku
(pip)
Jun 27, 2025
mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
Moderate
GHSA-fv92-fjc5-jj9h
was published
for
github.com/go-viper/mapstructure/v2
(Go)
Jun 27, 2025
filebrowser Sets Insecure File Permissions
Moderate
CVE-2025-52900
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 27, 2025
n8n allows open redirects via the /signin endpoint
Moderate
CVE-2025-49592
was published
for
n8n
(npm)
Jun 27, 2025
Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-5731
was published
for
org.infinispan:infinispan-cli-client
(Maven)
Jun 27, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
Moderate
CVE-2025-6442
was published
for
webrick
(RubyGems)
Jun 26, 2025
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
Moderate
CVE-2025-52894
was published
for
github.com/openbao/openbao
(Go)
Jun 26, 2025
OpenBao Inserts Sensitive Information into Log File when processing malformed data
Moderate
CVE-2025-52893
was published
for
github.com/openbao/openbao/sdk/v2
(Go)
Jun 26, 2025
iOS Simulator MCP Command Injection allowed via exec API
Moderate
CVE-2025-52573
was published
for
ios-simulator-mcp
(npm)
Jun 26, 2025
Gogs XSS allowed by stored call in PDF renderer
Moderate
CVE-2025-47943
was published
for
github.com/gogs/gogs
(Go)
Jun 26, 2025
Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter
Moderate
CVE-2025-53021
was published
for
moodle/moodle
(Composer)
Jun 24, 2025
Umbraco CMS disclosure of configured password requirements
Moderate
CVE-2025-49147
was published
for
Umbraco.Cms
(NuGet)
Jun 24, 2025
letmein connection limiter allows an arbitrary amount of simultaneous connections
Moderate
CVE-2025-52570
was published
for
letmeind
(Rust)
Jun 23, 2025
ProTip!
Advisories are also available from the
GraphQL API