GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,095 advisories
Filter by severity
chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
Moderate
GHSA-vrw8-fxc6-2r93
was published
for
github.com/go-chi/chi/v5
(Go)
Jun 20, 2025
Mattermost allows an unauthorized Guest user access to Playbook
Moderate
CVE-2025-3228
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows unauthorized channel member management through playbook runs
Moderate
CVE-2025-3227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Moderate
CVE-2025-52485
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Moderate
CVE-2025-52486
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
Velociraptor vulnerable to privilege escalation via UpdateConfig artifact
Moderate
CVE-2025-6264
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Jun 20, 2025
PowSyBl Core contains Polynomial REDoS’es
Moderate
CVE-2025-48058
was published
for
com.powsybl:powsybl-commons
(Maven)
Jun 19, 2025
urllib3 does not control redirects in browsers and Node.js
Moderate
CVE-2025-50182
was published
for
urllib3
(pip)
Jun 18, 2025
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Moderate
CVE-2025-50181
was published
for
urllib3
(pip)
Jun 18, 2025
Couchbase .NET SDK (client library) does not properly enable hostname verification for TLS certificates
Moderate
CVE-2025-49015
was published
for
CouchbaseNetClient
(NuGet)
Jun 18, 2025
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
Moderate
CVE-2025-50183
was published
for
@openlist-frontend/openlist-frontend
(npm)
Jun 18, 2025
OSV-SCALIBR's Container Image Unpacking Vulnerable to Arbitrary File Write via Path Traversal
Moderate
CVE-2025-5981
was published
for
github.com/google/osv-scalibr
(Go)
Jun 18, 2025
wasmtime_jit_debug Dumps Undefined Memory by `JitDumpFile`
Moderate
GHSA-9ghp-w2hm-vfpf
was published
for
wasmtime-jit-debug
(Rust)
Jun 17, 2025
Mezzanine CMS has a Stored Cross-Site Scripting (XSS) vulnerability in the displayable_links_js function
Moderate
CVE-2025-6050
was published
for
Mezzanine
(pip)
Jun 17, 2025
python-a2a has a path traversal in the create_workflow function
Moderate
CVE-2025-6167
was published
for
python-a2a
(pip)
Jun 17, 2025
pycares has a Use-After-Free Vulnerability
Moderate
GHSA-5qpg-rh4j-qp35
was published
for
pycares
(pip)
Jun 16, 2025
New authd users logging in via SSH are members of the root group
Moderate
CVE-2025-5689
was published
for
github.com/ubuntu/authd
(Go)
Jun 16, 2025
Apache Tomcat - Security constraint bypass for pre/post-resources
Moderate
CVE-2025-49125
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Weblate lacks rate limiting when verifying second factor
Moderate
CVE-2025-47951
was published
for
weblate
(pip)
Jun 16, 2025
XWiki does not require right warnings for notification displayer objects
Moderate
CVE-2025-49587
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
Moderate
CVE-2025-49583
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
Solon Vulnerable to Directory Traversal
Moderate
CVE-2025-46096
was published
for
org.noear:solon-faas-luffy
(Maven)
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Moderate
GHSA-9qv6-4pwm-m68f
was published
for
ibexa/fieldtype-richtext
(Composer)
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Moderate
GHSA-5r6x-g6jv-4v87
was published
for
ibexa/admin-ui
(Composer)
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Moderate
GHSA-vhgq-r8gx-5fpv
was published
for
ibexa/admin-ui-assets
(Composer)
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API