GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,111
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,539 advisories
Filter by severity
TinyEnv: Inline comments not stripped properly in .env values
Moderate
CVE-2025-58759
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
TinyEnv: Missing .env file not required — may cause unexpected behavior
Moderate
CVE-2025-58758
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Moderate
CVE-2025-58753
was published
for
copyparty
(pip)
Sep 9, 2025
TYPO3 backend modules have Broken Access Control
Moderate
CVE-2025-59017
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CSV download feature information disclosure
Moderate
CVE-2025-59019
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CMS exposes sensitive information in an error message
Moderate
CVE-2025-59016
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
TYPO3 Bookmark Toolbar vulnerable to denial of service
Moderate
CVE-2025-59014
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CMS has an open‑redirect vulnerability
Moderate
CVE-2025-59013
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
TYPO3 CMS uses insufficient entropy when generating passwords
Moderate
CVE-2025-59015
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Moderate
CVE-2025-58782
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Sep 8, 2025
xgrammar vulnerable to denial of service by huge enum grammar
Moderate
CVE-2025-58446
was published
for
xgrammar
(pip)
Sep 5, 2025
secrets-store-sync-controller discloses service account tokens in logs
Moderate
CVE-2025-7445
was published
for
sigs.k8s.io/secrets-store-sync-controller
(Go)
Sep 5, 2025
FS2 half-shutdown of socket during TLS handshake may result in spin loop on opposite side
Moderate
CVE-2025-58369
was published
for
co.fs2:fs2-io_0.26
(Maven)
Sep 5, 2025
Presta Shop vulnerable to email enumeration
Moderate
CVE-2025-51586
was published
for
prestashop/prestashop
(Composer)
Sep 4, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
Memos Vulnerable to Path Traversal via the CreateResource Endpoint
Moderate
CVE-2025-56760
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
Memos Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2025-56761
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
Mautic Vulnerable to User Enumeration via Response Timing
Moderate
CVE-2025-9824
was published
for
mautic/core
(Composer)
Sep 3, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Moderate
CVE-2025-9823
was published
for
mautic/core
(Composer)
Sep 3, 2025
Mautic vulnerable to secret data extraction via elfinder
Moderate
CVE-2025-9822
was published
for
mautic/core
(Composer)
Sep 3, 2025
frost-core: refresh shares with smaller min_signers will reduce security of group
Moderate
CVE-2025-58359
was published
for
frost-core
(Rust)
Sep 3, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
ProTip!
Advisories are also available from the
GraphQL API