GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,309 advisories
Filter by severity
Node Denial of Service via kubelet Checkpoint API
Moderate
CVE-2025-0426
was published
for
k8s.io/kubernetes
(Go)
Feb 13, 2025
Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
High
CVE-2025-26511
was published
for
com.instaclustr:cassandra-lucene-index-plugin
(Maven)
Feb 13, 2025
Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
High
CVE-2025-1247
was published
for
io.quarkus:quarkus-rest
(Maven)
Feb 13, 2025
Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
Moderate
CVE-2024-46910
was published
for
org.apache.atlas:apache-atlas
(Maven)
Feb 13, 2025
Missing rate limit in MaysWind ezBookkeeping
Moderate
CVE-2024-57603
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain
Moderate
GHSA-6fgm-x6ff-w78f
was published
for
github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7
(Go)
Feb 12, 2025
Crayfish Allows Remote Code Execution via hypercube X-Islandora-Args Header
Critical
GHSA-c2p2-hgjg-9r3f
was published
for
islandora/crayfish
(Composer)
Feb 12, 2025
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
Critical
GHSA-vjh7-7g9h-fjfh
was published
for
elliptic
(npm)
Feb 12, 2025
parse-duration has a Regex Denial of Service that results in event loop delay and out of memory
High
CVE-2025-25283
was published
for
parse-duration
(npm)
Feb 12, 2025
Inefficient Regular Expression Complexity in koa
Critical
CVE-2025-25200
was published
for
koa
(npm)
Feb 12, 2025
go-crypto-winnative BCryptGenerateSymmetricKey memory leak
High
CVE-2025-25199
was published
for
github.com/microsoft/go-crypto-winnative
(Go)
Feb 12, 2025
Possible Log Injection in Rack::CommonLogger
Moderate
CVE-2025-25184
was published
for
rack
(RubyGems)
Feb 12, 2025
Unencrypted transmission in Temporal api-go library
Low
CVE-2025-1243
was published
for
go.temporal.io/api
(Go)
Feb 12, 2025
GeoNetwork search end-point information disclosure in response headers
Moderate
CVE-2024-32037
was published
for
org.geonetwork-opensource:gn-services
(Maven)
Feb 11, 2025
Improper Authorization vulnerability in Magento and Adobe Commerce
Critical
CVE-2025-24434
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
Moderate
CVE-2024-52067
was published
for
org.apache.nifi:nifi-framework-core
(Maven)
Feb 11, 2025
Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`
Moderate
CVE-2025-25202
was published
for
ash_authentication
(Erlang)
Feb 11, 2025
Vulnerable OpenSSL included in cryptography wheels
Low
CVE-2024-12797
was published
for
cryptography
(pip)
Feb 11, 2025
Distribution's token authentication allows to inject an untrusted signing key in a JWT
High
CVE-2025-24976
was published
for
github.com/distribution/distribution/v3
(Go)
Feb 11, 2025
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical
CVE-2024-12366
was published
for
pandasai
(pip)
Feb 11, 2025
Server-side Request Forgery (SSRF) in hackney
Low
CVE-2025-1211
was published
for
hackney
(Erlang)
Feb 11, 2025
Authentication bypass in @sap/approuter
High
CVE-2025-24876
was published
for
@sap/approuter
(npm)
Feb 11, 2025
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Moderate
GHSA-v7pc-74h8-xq2h
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Authentication Bypass by Spoofing in OPC UA .NET Standard Stack
Moderate
CVE-2024-42513
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API