GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,835 advisories
Filter by severity
Ruby SAML allows remote Denial of Service (DoS) with compressed SAML responses
High
CVE-2025-25293
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-25292
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
Critical
CVE-2025-25291
was published
for
ruby-saml
(RubyGems)
Mar 12, 2025
gnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
High
CVE-2025-57801
was published
for
github.com/consensys/gnark
(Go)
Aug 22, 2025
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
sha.js is missing type checks leading to hash rewind and passing on crafted data
Critical
CVE-2025-9288
was published
for
sha.js
(npm)
Aug 21, 2025
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
Critical
CVE-2025-9287
was published
for
cipher-base
(npm)
Aug 21, 2025
Decap CMS Cross Site Scripting (XSS) vulnerability
Low
CVE-2025-57520
was published
for
decap-cms
(npm)
Sep 10, 2025
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Moderate
CVE-2025-58065
was published
for
flask-appbuilder
(pip)
Sep 11, 2025
XXL-JOB is vulnerable to SSRF attacks
Low
CVE-2025-7787
was published
for
com.xuxueli:xxl-job-core
(Maven)
Jul 18, 2025
Tonic has remotely exploitable denial of service vulnerability
Moderate
CVE-2024-47609
was published
for
tonic
(Rust)
Oct 1, 2024
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
High
CVE-2025-57817
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides has a Lack of Brute-Force Protections on Authentication Endpoints
Low
CVE-2025-57815
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides' Admin UI User Password Change Does Not Invalidate Current Session
Low
CVE-2025-57766
was published
for
ethyca-fides
(pip)
Sep 8, 2025
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
High
CVE-2025-54376
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Mockoon has a Path Traversal and LFI in the static file serving endpoint
High
CVE-2025-59049
was published
for
@mockoon/cli
(npm)
Mar 11, 2025
Atlantis Exposes Service Version Publicly on /status API Endpoint
Low
CVE-2025-58445
was published
for
github.com/runatlantis/atlantis
(Go)
Sep 5, 2025
SimpleXML vulnerable to XML External Entity (XXE)
Critical
CVE-2017-1000190
was published
for
org.simpleframework:simple-xml
(Maven)
May 14, 2022
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
Low
CVE-2025-9910
was published
for
jsondiffpatch
(npm)
Sep 11, 2025
Hono has Body Limit Middleware Bypass
Moderate
CVE-2025-59139
was published
for
hono
(npm)
Sep 12, 2025
httpsig-rs: HMAC verification is vulnerable to timing attack
Moderate
CVE-2025-59058
was published
for
httpsig
(Rust)
Sep 12, 2025
Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool
Moderate
CVE-2025-56556
was published
for
intelliants/subrion
(Composer)
Sep 11, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API