GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,494
Maven
5,000+
npm
4,137
NuGet
735
pip
3,945
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
133 advisories
Filter by severity
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
Vite's `server.fs` settings were not applied to HTML files
Low
CVE-2025-58752
was published
for
vite
(npm)
Sep 9, 2025
@backstage/backend-app-api leaks GitLab access tokens
High
CVE-2023-6944
was published
for
@backstage/backend-app-api
(npm)
Jan 4, 2024
@musistudio/claude-code-router has improper CORS configuration
High
CVE-2025-57755
was published
for
@musistudio/claude-code-router
(npm)
Aug 21, 2025
The AuthKit Remix Library renders sensitive auth data in HTML
High
CVE-2025-55009
was published
for
@workos-inc/authkit-remix
(npm)
Aug 8, 2025
The AuthKit React Router Library rendered sensitive auth data in HTML
High
CVE-2025-55008
was published
for
@workos-inc/authkit-react-router
(npm)
Aug 8, 2025
GitProxy Hidden Commits Injection
High
CVE-2025-54586
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
Directus' exact version number is exposed by the OpenAPI Spec
Moderate
CVE-2025-53887
was published
for
directus
(npm)
Jul 15, 2025
Directus tokens are not redacted in flow logs, exposing session credentials to all admin
Moderate
CVE-2025-53886
was published
for
directus
(npm)
Jul 15, 2025
docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token
Critical
CVE-2025-53624
was published
for
docusaurus-plugin-content-gists
(npm)
Jul 9, 2025
Cloudflare Vite plugin exposes secrets over the built-in dev server
Moderate
GHSA-4pfg-2mw5-f8jx
was published
for
@cloudflare/vite-plugin
(npm)
Jul 8, 2025
Passbolt Browser Extension leaks password information
Moderate
CVE-2024-33669
was published
for
passbolt-browser-extension
(npm)
Apr 26, 2024
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Low
CVE-2025-46720
was published
for
@keystone-6/core
(npm)
May 5, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Moderate
CVE-2025-31125
was published
for
vite
(npm)
Mar 31, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
Directus `search` query parameter allows enumeration of non permitted fields
Moderate
CVE-2025-30352
was published
for
directus
(npm)
Mar 26, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
Vite bypasses server.fs.deny when using ?raw??
Moderate
CVE-2025-30208
was published
for
vite
(npm)
Mar 25, 2025
Prototype Pollution Vulnerability in parse-git-config
High
CVE-2025-25975
was published
for
parse-git-config
(npm)
Mar 12, 2025
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
Critical
GHSA-vjh7-7g9h-fjfh
was published
for
elliptic
(npm)
Feb 12, 2025
MongoDB Driver may publish events containing authentication-related data
Moderate
CVE-2021-32050
was published
for
github.com/mongodb/mongo-swift-driver
(Composer)
Aug 29, 2023
ProTip!
Advisories are also available from the
GraphQL API