GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,067
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
10,960 advisories
Filter by severity
@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via welcome message
Moderate
CVE-2025-64758
was published
for
@dependencytrack/frontend
(npm)
Nov 17, 2025
lsFusion Platform has Path Traversal vulnerability
Moderate
CVE-2025-13262
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
vlife-base has Path Traversal vulnerability
Moderate
CVE-2025-13266
was published
for
io.github.wwwlike:vlife-base
(Maven)
Nov 17, 2025
lsFusion Platform has Path Traversal vulnerability
Moderate
CVE-2025-13261
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
Directus is Vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-64747
was published
for
directus
(npm)
Nov 14, 2025
Directus has Improper Permission Handling on Deleted Fields
Moderate
CVE-2025-64746
was published
for
directus
(npm)
Nov 14, 2025
Shopware 6's password recovery link does not expire after email change
Moderate
GHSA-2w46-vq8h-98vh
was published
for
shopware/core
(Composer)
Nov 14, 2025
PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
Moderate
CVE-2025-64714
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
js-yaml has prototype pollution in merge (<<)
Moderate
CVE-2025-64718
was published
for
js-yaml
(npm)
Nov 14, 2025
Mattermost allows system administrators to access password hashes and MFA secrets
Moderate
CVE-2025-11794
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost fails to properly restrict access to archived channel search API
Moderate
CVE-2025-11776
was published
for
github.com/mattermost/mattermost
(Go)
Nov 14, 2025
Mattermost does not enforce MFA on WebSocket connections
Moderate
CVE-2025-55070
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
Moderate
CVE-2025-55073
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Directus Vulnerable to Information Leakage in Existing Collections
Moderate
CVE-2025-64749
was published
for
@directus/api
(npm)
Nov 13, 2025
Directus's conceal fields are searchable if read permissions enabled
Moderate
CVE-2025-64748
was published
for
@directus/api
(npm)
Nov 13, 2025
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
Moderate
CVE-2025-64525
was published
for
astro
(npm)
Nov 13, 2025
Keycloak allows Binding to an Unrestricted IP Address
Moderate
CVE-2025-11538
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 13, 2025
sudo-rs doesn't record authenticating user properly in timestamp
Moderate
CVE-2025-64517
was published
for
sudo-rs
(Rust)
Nov 13, 2025
pgAdmin 4 has command injection vulnerability on Windows systems
Moderate
CVE-2025-12763
was published
for
pgadmin4
(pip)
Nov 13, 2025
Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details
Moderate
CVE-2025-64502
was published
for
parse-server
(npm)
Nov 13, 2025
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Moderate
CVE-2025-57697
was published
for
AstrBot
(pip)
Nov 7, 2025
Nuxt DevTools vulnerable to cross-site scripting (XSS)
Moderate
CVE-2025-52662
was published
for
@nuxt/devtools
(npm)
Nov 7, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Moderate
CVE-2025-64437
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API