GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,560 advisories
Filter by severity
Quarkus potentially leaks data when duplicating a duplicated context
Moderate
CVE-2025-49574
was published
for
io.quarkus:quarkus-vertx
(Maven)
Jun 23, 2025
MLFlow SSRF via gateway_proxy_handler
Moderate
CVE-2025-52967
was published
for
mlflow
(pip)
Jun 23, 2025
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
Mattermost allows an unauthorized Guest user access to Playbook
Moderate
CVE-2025-3228
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows unauthorized channel member management through playbook runs
Moderate
CVE-2025-3227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Moderate
CVE-2025-52485
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Moderate
CVE-2025-52486
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact
Moderate
CVE-2025-6264
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Jun 20, 2025
PowSyBl Core contains Polynomial REDoS’es
Moderate
CVE-2025-48058
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
urllib3 does not control redirects in browsers and Node.js
Moderate
CVE-2025-50182
was published
for
urllib3
(pip)
Jun 18, 2025
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Moderate
CVE-2025-50181
was published
for
urllib3
(pip)
Jun 18, 2025
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
Moderate
CVE-2025-49015
was published
for
CouchbaseNetClient
(NuGet)
Jun 18, 2025
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
Moderate
CVE-2025-50183
was published
for
@openlist-frontend/openlist-frontend
(npm)
Jun 18, 2025
OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal
Moderate
CVE-2025-5981
was published
for
github.com/google/osv-scalibr
(Go)
Jun 18, 2025
wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile`
Moderate
GHSA-9ghp-w2hm-vfpf
was published
for
wasmtime-jit-debug
(Rust)
Jun 17, 2025
Mezzanine CMS has a Stored Cross-Site Scripting (XSS) vulnerability in the displayable_links_js function
Moderate
CVE-2025-6050
was published
for
Mezzanine
(pip)
Jun 17, 2025
python-a2a has a path traversal in the create_workflow function
Moderate
CVE-2025-6167
was published
for
python-a2a
(pip)
Jun 17, 2025
pycares has a Use-After-Free Vulnerability
Moderate
GHSA-5qpg-rh4j-qp35
was published
for
pycares
(pip)
Jun 16, 2025
New authd users logging in via SSH are members of the root group
Moderate
CVE-2025-5689
was published
for
github.com/ubuntu/authd
(Go)
Jun 16, 2025
Apache Tomcat - Security constraint bypass for pre/post-resources
Moderate
CVE-2025-49125
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Weblate lacks rate limiting when verifying second factor
Moderate
CVE-2025-47951
was published
for
weblate
(pip)
Jun 16, 2025
XWiki does not require right warnings for notification displayer objects
Moderate
CVE-2025-49587
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
Moderate
CVE-2025-49583
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
Solon Vulnerable to Directory Traversal
Moderate
CVE-2025-46096
was published
for
org.noear:solon-faas-luffy
(Maven)
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Moderate
GHSA-9qv6-4pwm-m68f
was published
for
ibexa/fieldtype-richtext
(Composer)
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API