GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,411 advisories
Filter by severity
org.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming right
Critical
CVE-2025-32973
was published
for
org.xwiki.platform:xwiki-platform-component-wiki
(Maven)
Apr 29, 2025
Craft CMS Allows Remote Code Execution
Critical
CVE-2025-32432
was published
for
craftcms/cms
(Composer)
Apr 25, 2025
h11 accepts some malformed Chunked-Encoding bodies
Critical
CVE-2025-43859
was published
for
h11
(pip)
Apr 24, 2025
YoutubeDLSharp allows command injection on windows system due to non sanitized arguments
Critical
CVE-2025-43858
was published
for
YoutubeDLSharp
(NuGet)
Apr 23, 2025
org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API
Critical
CVE-2025-32969
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Apr 23, 2025
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
Critical
GHSA-ggpf-24jw-3fcw
was published
for
vllm
(pip)
Apr 23, 2025
Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2
Critical
CVE-2025-32965
was published
for
xrpl
(npm)
Apr 22, 2025
Wazuh server vulnerable to remote code execution
Critical
CVE-2025-24016
was published
for
github.com/wazuh/wazuh
(Go)
Apr 22, 2025
MCMS allows arbitrary file uploads in the ueditor component
Critical
CVE-2025-29287
was published
for
net.mingsoft:ms-mcms
(Maven)
Apr 21, 2025
Traefik affected by Go HTTP Request Smuggling Vulnerability
Critical
GHSA-5423-jcjm-2gpv
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
Apache ActiveMQ NMS OpenWire Client Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-29953
was published
for
Apache.NMS.ActiveMQ
(NuGet)
Apr 18, 2025
PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
Critical
CVE-2025-32434
was published
for
torch
(pip)
Apr 18, 2025
NATS Server may fail to authorize certain Jetstream admin APIs
Critical
CVE-2025-30215
was published
for
github.com/nats-io/nats-server/v2
(Go)
Apr 15, 2025
Dpanel's hard-coded JWT secret leads to remote code execution
Critical
CVE-2025-30206
was published
for
github.com/donknap/dpanel
(Go)
Apr 15, 2025
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
Argo Events users can gain privileged access to the host system and cluster with EventSource and Sensor CR
Critical
CVE-2025-32445
was published
for
github.com/argoproj/argo-events
(Go)
Apr 14, 2025
TigerVNC accessible via the network and not just via a UNIX socket as intended
Critical
CVE-2025-32428
was published
for
jupyter-remote-desktop-proxy
(pip)
Apr 12, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
Critical
GHSA-ccj3-5p93-8p42
was published
for
surrealdb
(Rust)
Apr 11, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Critical
CVE-2024-58136
was published
for
yiisoft/yii2
(Composer)
Apr 10, 2025
BentoML's runner server Vulnerable to Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-32375
was published
for
bentoml
(pip)
Apr 9, 2025
LNbits Lightning Network Payment System Vulnerable to Server-Side Request Forgery via LNURL Authentication Callback
Critical
CVE-2025-32013
was published
for
lnbits
(pip)
Apr 7, 2025
Duplicate Advisory: Langflow Vulnerable to Code Injection via the `/api/v1/validate/code` endpoint
Critical
GHSA-c995-4fw3-j39m
was published
for
langflow
(pip)
Apr 7, 2025
•
withdrawn
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
Critical
CVE-2025-27520
was published
for
bentoml
(pip)
Apr 4, 2025
pgAdmin 4 Vulnerable to Remote Code Execution
Critical
CVE-2025-2945
was published
for
pgadmin4
(pip)
Apr 3, 2025
pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering
Critical
CVE-2025-2946
was published
for
pgadmin4
(pip)
Apr 3, 2025
ProTip!
Advisories are also available from the
GraphQL API