GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,736
Maven
5,000+
npm
4,336
NuGet
764
pip
4,110
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,674 advisories
Filter by severity
Shopware Storefront Reflected XSS in Storefront Login Page
High
GHSA-6w82-v552-wjw2
was published
for
shopware/shopware
(Composer)
Dec 9, 2025
Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)
High
GHSA-j8g6-5gqc-mq36
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Filament multi-factor authentication (app) recovery codes can be used multiple times
High
GHSA-pvcv-q3q7-266g
was published
for
filament/filament
(Composer)
Dec 9, 2025
SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin
High
GHSA-4r66-7rcv-x46x
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
High
CVE-2025-67488
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
High
CVE-2025-66626
was published
for
github.com/argoproj/argo-workflows
(Go)
Dec 9, 2025
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
High
CVE-2025-65106
was published
for
langchain-core
(pip)
Nov 20, 2025
Elysia affected by arbitrary code injection through cookie config
High
CVE-2025-66457
was published
for
elysia
(npm)
Dec 9, 2025
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
High
GHSA-vp58-j275-797x
was published
for
better-auth
(npm)
Feb 24, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
High
CVE-2025-61928
was published
for
better-auth
(npm)
Oct 9, 2025
expr-eval does not restrict functions passed to the evaluate function
High
CVE-2025-12735
was published
for
expr-eval
(npm)
Nov 5, 2025
memos vulnerability allows the creation of arbitrary accounts
High
CVE-2025-65795
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
High
CVE-2025-66645
was published
for
nicegui
(pip)
Dec 9, 2025
Babylon Nil BlockHash in BLS vote extensions triggers panics in consensus handlers
High
GHSA-m6wq-66p2-c8pc
was published
for
github.com/babylonlabs-io/babylon
(Go)
Dec 8, 2025
ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login
High
CVE-2025-67495
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 Login
High
GHSA-pfrf-9r5f-73f5
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)
High
CVE-2025-66631
was published
for
Csla
(NuGet)
Dec 8, 2025
Critical Use-After-Free in Wasmi's Linear Memory
High
CVE-2025-66627
was published
for
wasmi
(Rust)
Dec 8, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionality
High
CVE-2025-65346
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 4, 2025
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
Mattermost Server does not properly restrict use of slash commands
High
CVE-2017-18886
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Podman Creates Temporary File with Insecure Permissions
High
CVE-2025-4953
was published
for
github.com/containers/podman/v5
(Go)
Sep 16, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
yawkat LZ4 Java has a possible information leak in Java safe decompressor
High
CVE-2025-66566
was published
for
at.yawk.lz4:lz4-java
(Maven)
Dec 5, 2025
ProTip!
Advisories are also available from the
GraphQL API