GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
214 advisories
Filter by severity
@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser
Low
GHSA-xffm-g5w8-qvg7
was published
for
@eslint/plugin-kit
(npm)
Jul 18, 2025
Duplicate Advisory: Koa Open Redirect via Referrer Header (User-Controlled)
Low
GHSA-mvw6-62qv-vmqf
was published
for
koa
(npm)
Jul 25, 2025
•
withdrawn
Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter
Low
CVE-2025-43712
was published
for
generator-jhipster
(npm)
Jul 25, 2025
•
withdrawn
Koa Open Redirect via Referrer Header (User-Controlled)
Low
CVE-2025-8129
was published
for
koa
(npm)
Jul 29, 2025
tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter
Low
CVE-2025-54798
was published
for
tmp
(npm)
Aug 6, 2025
HFS user adding a "web link" in HFS is vulnerable to "target=_blank" exploit
Low
GHSA-xcxh-6cv4-q8p8
was published
for
hfs
(npm)
Aug 12, 2025
Template Secret leakage in logs in Scaffolder when using `fetch:template`
Low
CVE-2025-55285
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Aug 15, 2025
ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/users.js
Low
CVE-2025-9095
was published
for
express-gateway
(npm)
Aug 18, 2025
ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
Low
CVE-2025-9096
was published
for
express-gateway
(npm)
Aug 18, 2025
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package
Low
CVE-2025-58064
was published
for
@ckeditor/ckeditor5-clipboard
(npm)
Sep 3, 2025
Vite's `server.fs` settings were not applied to HTML files
Low
CVE-2025-58752
was published
for
vite
(npm)
Sep 9, 2025
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
Decap CMS Cross Site Scripting (XSS) vulnerability
Low
CVE-2025-57520
was published
for
decap-cms
(npm)
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API