GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,368
Maven
5,000+
npm
3,988
NuGet
720
pip
3,779
Pub
12
RubyGems
926
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
196 advisories
Filter by severity
string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS)
Low
CVE-2025-45143
was published
for
string-math
(npm)
Jun 30, 2025
Taylor has race condition in /get-patch that allows purchase token replay
Low
GHSA-vh5j-5fhq-9xwg
was published
for
taylored
(npm)
Jun 27, 2025
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode
Low
CVE-2025-6624
was published
for
github.com/snyk/go-application-framework
(Go)
Jun 26, 2025
Valid ECDSA signatures erroneously rejected in Elliptic
Low
CVE-2024-48948
was published
for
elliptic
(npm)
Oct 15, 2024
Withdrawn Advisory: microlight.js has a null pointer dereference vulnerability
Low
CVE-2025-45525
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
Withdrawn Advisory: microlight allows a denial of service
Low
CVE-2025-45526
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
Information exposure in Next.js dev server due to lack of origin verification
Low
CVE-2025-48068
was published
for
next
(npm)
May 28, 2025
brace-expansion Regular Expression Denial of Service vulnerability
Low
CVE-2025-5889
was published
for
brace-expansion
(npm)
Jun 9, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
Suspended Directus user can continue to use session token to access API
Low
CVE-2025-30351
was published
for
@directus/api
(npm)
Mar 26, 2025
auth-js Vulnerable to Insecure Path Routing from Malformed User Input
Low
CVE-2025-48370
was published
for
@supabase/auth-js
(npm)
May 27, 2025
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
Low
CVE-2025-46653
was published
for
formidable
(npm)
Apr 26, 2025
undici Denial of Service attack via bad certificate data
Low
CVE-2025-47279
was published
for
undici
(npm)
May 15, 2025
Next.js Race Condition to Cache Poisoning
Low
CVE-2025-32421
was published
for
next
(npm)
May 15, 2025
Trix vulnerable to Cross-site Scripting on copy & paste
Low
CVE-2025-46812
was published
for
trix
(npm)
May 8, 2025
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Low
CVE-2025-46720
was published
for
@keystone-6/core
(npm)
May 5, 2025
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
AngularJS improperly sanitizes SVG elements
Low
CVE-2025-0716
was published
for
angular
(npm)
Apr 29, 2025
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46328
was published
for
snowflake-sdk
(npm)
Apr 28, 2025
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
Low
GHSA-qc59-cxj2-c2w4
was published
for
aws-cdk-lib
(npm)
Apr 15, 2025
cookie accepts cookie name, path, and domain with out of bounds characters
Low
CVE-2024-47764
was published
for
cookie
(npm)
Oct 4, 2024
AWS CDK CodePipeline: trusted entities are too broad
Low
GHSA-5pq3-h73f-66hr
was published
for
aws-cdk-lib
(npm)
Mar 24, 2025
React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
Low
CVE-2025-3191
was published
for
react-draft-wysiwyg
(npm)
Apr 4, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
ProTip!
Advisories are also available from the
GraphQL API