GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,459 advisories
Filter by severity
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
Critical
CVE-2025-59545
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
H2O affected by a deserialization vulnerability
Critical
CVE-2025-6544
was published
for
ai.h2o:h2o-core
(Maven)
Sep 22, 2025
InvokeAI has External Control of File Name or Path
Critical
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
jinjava has Sandbox Bypass via JavaType-Based Deserialization
Critical
CVE-2025-59340
was published
for
com.hubspot.jinjava:jinjava
(Maven)
Sep 17, 2025
Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
Critical
GHSA-hf6h-9wq7-hmjg
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
GHSA-4vr7-g93g-cf6m
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch
Critical
GHSA-j424-mc44-f4hj
was published
for
picklescan
(pip)
Sep 17, 2025
•
withdrawn
Spring Expression language property modification using Spring Cloud Gateway Server WebFlux
Critical
CVE-2025-41243
was published
for
org.springframework.cloud:spring-cloud-gateway-server-webflux
(Maven)
Sep 16, 2025
Flowise has arbitrary file access due to missing chat flow id validation
Critical
GHSA-q67q-549q-p849
was published
for
flowise
(npm)
Sep 15, 2025
Flowise has an Arbitrary File Read
Critical
GHSA-99pg-hqvx-r4gf
was published
for
flowise
(npm)
Sep 15, 2025
Flowise has Remote Code Execution vulnerability
Critical
CVE-2025-59528
was published
for
flowise
(npm)
Sep 15, 2025
FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
GHSA-7944-7c6r-55vv
was published
for
flowise
(npm)
Sep 15, 2025
mcp-kubernetes-server has an OS Command Injection vulnerability
Critical
CVE-2025-59377
was published
for
mcp-kubernetes-server
(pip)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59360
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59359
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59361
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Critical
CVE-2025-58434
was published
for
flowise
(npm)
Sep 12, 2025
Prebid-universal-creative latest on npm briefly compromised
Critical
CVE-2025-59039
was published
for
prebid-universal-creative
(npm)
Sep 11, 2025
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
Picklescan Bypass is Possible via File Extension Mismatch
Critical
CVE-2025-10155
was published
for
picklescan
(pip)
Sep 10, 2025
Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
Critical
CVE-2025-10156
was published
for
picklescan
(pip)
Sep 10, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
Critical
CVE-2025-10157
was published
for
picklescan
(pip)
Sep 10, 2025
Magento Community Edition Improper Input Validation vulnerability
Critical
CVE-2025-54236
was published
for
magento/community-edition
(Composer)
Sep 9, 2025
pREST has a Systemic SQL Injection Vulnerability
Critical
CVE-2025-58450
was published
for
github.com/prest/prest/v2
(Go)
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API