GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,577 advisories
Filter by severity
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-52c5-vh7f-26fx
was published
for
prosemirror_to_html
(RubyGems)
Nov 6, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
Magento allows attackers to alter the price of items
High
CVE-2021-36030
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Path Traversal vulnerability via the `theme[preview_image]` parameter
High
CVE-2021-36031
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2021-36033
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento improper authorization vulnerability
High
CVE-2021-36029
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the Widgets Update Layout
High
CVE-2021-36022
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the 'City' field
High
CVE-2021-36020
was published
for
magento/community-edition
(Composer)
May 24, 2022
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Moderate
CVE-2025-64437
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Moderate
CVE-2025-64329
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Low
CVE-2025-64326
was published
for
weblate
(pip)
Nov 5, 2025
OpenMage vulnerable to XSS in Admin Notifications
Moderate
CVE-2025-64174
was published
for
openmage/magento-lts
(Composer)
Nov 3, 2025
Apollo Router Affected by an Access Control Bypass on Polymorphic Types
High
CVE-2025-64173
was published
for
apollo-router
(Rust)
Nov 6, 2025
runc container escape with malicious config due to /dev/console mount and related races
High
CVE-2025-52565
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
runc container escape via "masked path" abuse due to mount race conditions
High
CVE-2025-31133
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
containerd affected by a local privilege escalation via wide permissions on CRI directory
High
CVE-2024-25621
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
@react-native-community/cli has arbitrary OS command injection
Critical
CVE-2025-11953
was published
for
@react-native-community/cli
(npm)
Nov 3, 2025
ProTip!
Advisories are also available from the
GraphQL API