Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,154 advisories

Loading
Next.js Content Injection Vulnerability for Image Optimization Moderate
CVE-2025-55173 was published for next (npm) Aug 29, 2025
kristianmagas medikoo
TinyEnv: Inline comments not stripped properly in .env values Moderate
CVE-2025-58759 was published for datahihi1/tiny-env (Composer) Sep 9, 2025
github.com/google/nftable IP addresses were encoded in the wrong byte order Moderate
CVE-2024-6284 was published for github.com/google/nftables (Go) Jul 4, 2024
Element Plus Link component (el-link) implements insufficient input validation for the href attribute Moderate
CVE-2025-57665 was published for element-plus (npm) Sep 9, 2025
Vaadin Platform possible file bypass via upload validation on the server-side Moderate
GHSA-c7v7-rqfm-f44j was published for com.vaadin:vaadin (Maven) Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side Moderate
GHSA-94g8-xv23-7656 was published for com.vaadin:vaadin-upload-flow (Maven) Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side Moderate
CVE-2025-9467 was published for com.vaadin:vaadin-server (Maven) Sep 4, 2025
Spoofing attack in swagger-ui Moderate
CVE-2018-25031 was published for org.webjars:swagger-ui (Maven) Mar 12, 2022
AndrzejBiernacki2010
, aka 'Microsoft Edge for Android Spoofing Vulnerability'. Moderate Unreviewed
CVE-2020-17153 was published May 24, 2022
, aka 'Azure DevOps Server Spoofing Vulnerability'. Moderate Unreviewed
CVE-2020-17135 was published May 24, 2022
, aka 'Azure DevOps Server and Team Foundation Services Spoofing Vulnerability'. Moderate Unreviewed
CVE-2020-17145 was published May 24, 2022
An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10... Moderate Unreviewed
CVE-2025-57220 was published Aug 28, 2025
ProTip! Advisories are also available from the GraphQL API