GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,807
Erlang
36
GitHub Actions
31
Go
2,390
Maven
5,000+
npm
4,026
NuGet
720
pip
3,815
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,555 advisories
Filter by severity
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
High
CVE-2025-54128
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
@translated/lara-mcp vulnerable to command injection in import_tmx tool
High
CVE-2025-53832
was published
for
@translated/lara-mcp
(npm)
Jul 21, 2025
NodeJS version of the HAX CMS application is distributed with Default Secrets
High
CVE-2025-54137
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
High
CVE-2025-54313
was published
for
@pkgr/core
(npm)
Jul 19, 2025
Alchemy Non-SMA and Webauthn Account Security Advisory
High
GHSA-56r6-ccm5-8hg3
was published
for
@account-kit/smart-contracts
(npm)
Jul 21, 2025
Denial of Service in @hapi/subtext
High
GHSA-3wqh-h42r-x8fq
was published
for
@hapi/subtext
(npm)
Sep 3, 2020
Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
High
CVE-2025-54075
was published
for
@nuxtjs/mdc
(npm)
Jul 20, 2025
@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser
High
GHSA-xffm-g5w8-qvg7
was published
for
@eslint/plugin-kit
(npm)
Jul 18, 2025
Duplicate Advisory: Prototype Pollution in min-dash
High
GHSA-fm93-fhh2-cg2c
was published
for
min-dash
(npm)
Jan 27, 2022
•
withdrawn
Duplicate Advisory: Prototype Pollution in klona
High
GHSA-4r97-78gf-q24v
was published
for
klona
(npm)
Sep 4, 2020
•
withdrawn
Multer vulnerable to Denial of Service via unhandled exception from malformed request
High
CVE-2025-7338
was published
for
multer
(npm)
Jul 17, 2025
GitHub Kanban MCP Server vulnerable to Command Injection
High
CVE-2025-53818
was published
for
@sunwood-ai-labs/github-kanban-mcp-server
(npm)
Jul 15, 2025
chromedriver Downloads Resources over HTTP
High
CVE-2016-10579
was published
for
chromedriver
(npm)
Feb 18, 2019
ag-grid Cross-Site Scripting vulnerability
High
GHSA-7p6w-x2gr-rrf8
was published
for
ag-grid
(npm)
Sep 2, 2020
@clerk/backend Performs Insufficient Verification of Data Authenticity
High
CVE-2025-53548
was published
for
@clerk/astro
(npm)
Jul 9, 2025
libwebp: OOB write in BuildHuffmanTable
High
CVE-2023-4863
was published
for
Pillow
(Go)
Sep 12, 2023
MCP Server Kubernetes vulnerable to command injection in several tools
High
CVE-2025-53355
was published
for
mcp-server-kubernetes
(npm)
Jul 8, 2025
Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection
High
CVE-2025-53372
was published
for
node-code-sandbox-mcp
(npm)
Jul 8, 2025
Next.JS vulnerability can lead to DoS via cache poisoning
High
CVE-2025-49826
was published
for
next
(npm)
Jul 3, 2025
react-native-keys insecurely stores encryption cipher and Base64 chunks
High
CVE-2025-45001
was published
for
react-native-keys
(npm)
Jun 9, 2025
@modelcontextprotocol/server-filesystem vulnerability allows for path validation bypass via colliding path prefix
High
CVE-2025-53110
was published
for
@modelcontextprotocol/server-filesystem
(npm)
Jul 1, 2025
@modelcontextprotocol/server-filesystem allows for path validation bypass via prefix matching and symlink handling
High
CVE-2025-53109
was published
for
@modelcontextprotocol/server-filesystem
(npm)
Jul 1, 2025
ProTip!
Advisories are also available from the
GraphQL API