GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,122 advisories
Filter by severity
Axios is vulnerable to DoS attack through lack of data size check
High
CVE-2025-58754
was published
for
axios
(npm)
Sep 11, 2025
Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6484
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
•
withdrawn
Next.js Improper Middleware Redirect Handling Leads to SSRF
Moderate
CVE-2025-57822
was published
for
next
(npm)
Aug 29, 2025
Next.js Content Injection Vulnerability for Image Optimization
Moderate
CVE-2025-55173
was published
for
next
(npm)
Aug 29, 2025
Prebid-universal-creative latest on npm briefly compromised
Critical
CVE-2025-59039
was published
for
prebid-universal-creative
(npm)
Sep 11, 2025
Prebid.js NPM package briefly compromised
High
CVE-2025-59038
was published
for
prebid.js
(npm)
Sep 11, 2025
Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage
High
CVE-2025-59052
was published
for
@angular/platform-server
(npm)
Sep 10, 2025
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
Mockoon has a Path Traversal and LFI in the static file serving endpoint
High
CVE-2025-59049
was published
for
@mockoon/cli
(npm)
Mar 11, 2025
Claude Code rg vulnerability does not protect against approval prompt bypass
High
CVE-2025-58764
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Authorization Bypass in Next.js Middleware
Critical
CVE-2025-29927
was published
for
next
(npm)
Mar 21, 2025
Next.js authorization bypass vulnerability
High
CVE-2024-51479
was published
for
next
(npm)
Dec 17, 2024
DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware
High
CVE-2025-59037
was published
for
@duckdb/duckdb-wasm
(npm)
Sep 9, 2025
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
High
CVE-2025-58444
was published
for
@modelcontextprotocol/inspector
(npm)
Sep 8, 2025
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
KaTeX \htmlData does not validate attribute names
Moderate
CVE-2025-23207
was published
for
katex
(npm)
Jan 17, 2025
Decap CMS Cross Site Scripting (XSS) vulnerability
Low
CVE-2025-57520
was published
for
decap-cms
(npm)
Sep 10, 2025
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Improper Neutralization of Special Elements used in a Command in Shell-quote
Critical
CVE-2021-42740
was published
for
shell-quote
(npm)
May 24, 2022
Webrecorder packages are vulnerable to XSS through 404 error handling logic
High
CVE-2025-58765
was published
for
@webrecorder/archivewebpage
(npm)
Sep 10, 2025
CodeceptJS's incomprehensive sanitation can lead to Command Injection
Critical
CVE-2025-57285
was published
for
codeceptjs
(npm)
Sep 8, 2025
N8N's Chat Trigger component is vulnerable to XSS
High
CVE-2025-56265
was published
for
@n8n/n8n-nodes-langchain
(npm)
Sep 8, 2025
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API