GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
263 advisories
Filter by severity
Rancher: Restricted Administrator can change Administrator's passwords
Critical
CVE-2025-23391
was published
for
github.com/rancher/rancher
(Go)
Apr 1, 2025
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
Critical
CVE-2025-30223
was published
for
github.com/beego/beego
(Go)
Mar 31, 2025
ingress-nginx admission controller RCE escalation
Critical
CVE-2025-1974
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace
Critical
CVE-2025-29922
was published
for
github.com/kcp-dev/kcp
(Go)
Mar 20, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002)
Critical
GHSA-h2rp-8vpx-q9r4
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 13, 2025
IBC-Go: Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt
Critical
GHSA-4wf3-5qj9-368v
was published
for
github.com/cosmos/ibc-go
(Go)
Mar 12, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-33cr-m232-xqch
was published
for
github.com/cheqd/cheqd-node
(Go)
Mar 11, 2025
Fleet has SAML authentication vulnerability due to improper SAML response validation
Critical
CVE-2025-27509
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 6, 2025
IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
Critical
CVE-2025-27507
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement
Critical
GHSA-jg6f-48ff-5xrw
was published
for
github.com/cosmos/ibc-go
(Go)
Feb 28, 2025
Mattermost allows reading arbitrary files related to importing boards
Critical
CVE-2025-25279
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Mattermost allows reading arbitrary files
Critical
CVE-2025-20051
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
MaysWind ezBookkeeping has Improper Privilege Management
Critical
CVE-2024-57604
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
WhoDB has a path traversal opening Sqlite3 database
Critical
CVE-2025-24786
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
go-git has an Argument Injection via the URL field
Critical
CVE-2025-21613
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 6, 2025
Gogs has an argument Injection in the built-in SSH server
Critical
CVE-2024-39930
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
Critical
CVE-2024-39932
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Gogs allows deletion of internal files
Critical
CVE-2024-39931
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
GoCast OS Command Injection vulnerability
Critical
CVE-2024-28892
was published
for
github.com/mayuresh82/gocast
(Go)
Dec 20, 2024
Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto
Critical
CVE-2024-45337
was published
for
golang.org/x/crypto
(Go)
Dec 11, 2024
Osmedeus Web Server Vulnerable to Stored XSS, Leading to RCE
Critical
CVE-2024-51735
was published
for
github.com/j3ssie/osmedeus
(Go)
Nov 5, 2024
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
Critical
CVE-2024-0132
was published
for
github.com/NVIDIA/nvidia-container-toolkit
(Go)
Oct 29, 2024
Withdrawn Advisory: go-mysql affected by go.uuid's Predictable UUID Identifiers
Critical
GHSA-rc7v-65v6-m2v3
was published
for
github.com/go-mysql-org/go-mysql
(Go)
Oct 28, 2024
•
withdrawn
github.com/crossplane/crossplane: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses
Critical
GHSA-7h65-4p22-39j6
was published
for
github.com/crossplane/crossplane
(Go)
Oct 25, 2024
RKE2 allows privilege escalation in Windows nodes due to Insecure Access Control Lists
Critical
GHSA-x7xj-jvwp-97rv
was published
for
github.com/rancher/rke2
(Go)
Oct 25, 2024
ProTip!
Advisories are also available from the
GraphQL API