GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,532 advisories
Filter by severity
Apollo Router Affected by an Access Control Bypass on Polymorphic Types
High
CVE-2025-64173
was published
for
apollo-router
(Rust)
Nov 6, 2025
Apollo Router Improperly Enforces Renamed Access Control Directives
High
CVE-2025-64347
was published
for
apollo-router
(Rust)
Nov 6, 2025
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-52c5-vh7f-26fx
was published
for
prosemirror_to_html
(RubyGems)
Nov 6, 2025
containerd affected by a local privilege escalation via wide permissions on CRI directory
High
CVE-2024-25621
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
High
CVE-2025-64439
was published
for
langgraph-checkpoint
(pip)
Nov 5, 2025
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
High
CVE-2025-64430
was published
for
parse-server
(npm)
Nov 5, 2025
IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering
High
CVE-2025-64431
was published
for
github.com/zitadel/zitadel
(Go)
Nov 5, 2025
youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects
High
CVE-2025-62596
was published
for
youki
(Rust)
Nov 5, 2025
youki container escape via "masked path" abuse due to mount race conditions
High
CVE-2025-62161
was published
for
youki
(Rust)
Nov 5, 2025
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
High
CVE-2025-52881
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
runc container escape with malicious config due to /dev/console mount and related races
High
CVE-2025-52565
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
runc container escape via "masked path" abuse due to mount race conditions
High
CVE-2025-31133
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
High
CVE-2025-64458
was published
for
django
(pip)
Nov 5, 2025
expr-eval does not restrict functions passed to the evaluate function
High
CVE-2025-12735
was published
for
expr-eval
(npm)
Nov 5, 2025
MARIN3R: Cross-Namespace Vulnerability in the Operator
High
CVE-2025-64171
was published
for
github.com/3scale-sre/marin3r
(Go)
Nov 4, 2025
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
High
CVE-2025-64184
was published
for
dosage
(pip)
Nov 4, 2025
Jellysweep uses uncontrolled data in image cache API endpoint
High
CVE-2025-64178
was published
for
github.com/jon4hz/jellysweep
(Go)
Nov 4, 2025
motionEye vulnerable to RCE via unsanitized motion config parameter
High
CVE-2025-60787
was published
for
motioneye
(pip)
Nov 3, 2025
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
High
CVE-2025-47776
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Agno session state overwrites between different sessions/users
High
CVE-2025-64168
was published
for
agno
(pip)
Oct 31, 2025
Brotli is vulnerable to a denial of service (DoS) attack due to decompression
High
CVE-2025-6176
was published
for
brotli
(pip)
Oct 31, 2025
sqls-server/sqls is vulnerable to command injection in the config command
High
CVE-2025-61141
was published
for
github.com/sqls-server/sqls
(Go)
Oct 30, 2025
Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12060
was published
for
keras
(pip)
Oct 30, 2025
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
High
CVE-2025-64112
was published
for
statamic/cms
(Composer)
Oct 30, 2025
ProTip!
Advisories are also available from the
GraphQL API