GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,114
NuGet
735
pip
3,934
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
12,418 advisories
Filter by severity
Mattermost Confluence Plugin has Missing Authorization vulnerability
Low
CVE-2025-53857
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Litestar has potential log injection in exception logging
Low
GHSA-674p-xv2x-rf3g
was published
for
litestar
(pip)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Low
CVE-2025-49221
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
ember-source Cross-site Scripting vulnerability
Low
CVE-2014-0046
was published
for
ember-source
(RubyGems)
Aug 28, 2018
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low
CVE-2025-54999
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.
Low
Unreviewed
CVE-2025-27536
was published
Aug 11, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release...
Low
Unreviewed
CVE-2025-27562
was published
Aug 11, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer...
Low
Unreviewed
CVE-2025-26690
was published
Aug 11, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.
Low
Unreviewed
CVE-2025-25212
was published
Aug 11, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release...
Low
Unreviewed
CVE-2025-24925
was published
Aug 11, 2025
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release...
Low
Unreviewed
CVE-2025-24844
was published
Aug 11, 2025
In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web...
Low
Unreviewed
CVE-2025-52136
was published
Aug 10, 2025
A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic....
Low
Unreviewed
CVE-2025-8774
was published
Aug 9, 2025
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has...
Low
Unreviewed
CVE-2025-8751
was published
Aug 9, 2025
Apache Tomcat - CGI security constraint bypass
Low
CVE-2025-46701
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
May 29, 2025
Apache Tomcat Rewrite rule bypass
Low
CVE-2025-31651
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This...
Low
Unreviewed
CVE-2025-8708
was published
Aug 8, 2025
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
Low
CVE-2024-5798
was published
for
github.com/hashicorp/vault
(Go)
Jun 12, 2024
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25...
Low
Unreviewed
CVE-2024-56339
was published
Aug 7, 2025
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors
Low
GHSA-vh9x-phq6-fx54
was published
for
github.com/rs/cors
(Go)
Aug 6, 2025
•
withdrawn
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17...
Low
Unreviewed
CVE-2024-5528
was published
Feb 5, 2025
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive...
Low
Unreviewed
CVE-2025-38746
was published
Aug 6, 2025
ProTip!
Advisories are also available from the
GraphQL API