GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,800
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,005
NuGet
720
pip
3,805
Pub
12
RubyGems
927
Rust
986
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,186 advisories
Filter by severity
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Moderate
CVE-2025-48924
was published
for
commons-lang:commons-lang
(Maven)
Jul 11, 2025
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26795
was published
for
org.apache.iotdb:iotdb-jdbc
(Maven)
May 14, 2025
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
Moderate
CVE-2025-53506
was published
for
org.apache.tomcat:tomcat-coyote
(Maven)
Jul 10, 2025
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
Moderate
CVE-2025-52520
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Jul 10, 2025
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
Moderate
CVE-2025-52434
was published
for
org.apache.tomcat:tomcat-util
(Maven)
Jul 10, 2025
MODX Revolution vulnerable to XSS attack through its User Photo field
Moderate
CVE-2018-20755
was published
for
modx/revolution
(Composer)
May 14, 2022
MODX Revolution allows XSS via document resources
Moderate
CVE-2018-20756
was published
for
modx/revolution
(Composer)
May 14, 2022
MODX Revolution allows XSS through extended user fields
Moderate
CVE-2018-20757
was published
for
modx/revolution
(Composer)
May 14, 2022
phpThumb is vulnerable to Command Injection through its gif_outputAsJpeg function
Moderate
CVE-2025-52994
was published
for
james-heinrich/phpthumb
(Composer)
Jul 11, 2025
MODX vulnerability allows for XSS via user settings parameters
Moderate
CVE-2018-20758
was published
for
modx/revolution
(Composer)
May 13, 2022
Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation
Moderate
CVE-2025-53549
was published
for
matrix-sdk
(Rust)
Jul 10, 2025
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Moderate
CVE-2025-3933
was published
for
transformers
(pip)
Jul 11, 2025
Better Call routing bug can lead to Cache Deception
Moderate
GHSA-hq75-xg7r-rx6c
was published
for
better-call
(npm)
Jul 11, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
Apache Answer: Avatar URL leaked user email addresses
Moderate
CVE-2024-40761
was published
for
github.com/apache/incubator-answer
(Go)
Sep 25, 2024
@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation
Moderate
CVE-2025-53626
was published
for
@pdfme/common
(npm)
Jul 10, 2025
Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability
Moderate
CVE-2024-28168
was published
for
org.apache.xmlgraphics:fop-core
(Maven)
Oct 9, 2024
Keycloak vulnerable to phishing attacks through its Review Profile section
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
Parse Server exposes the data schema via GraphQL API
Moderate
CVE-2025-53364
was published
for
parse-server
(npm)
Jul 10, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
taro-css-to-react-native Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5896
was published
for
taro-css-to-react-native
(npm)
Jun 9, 2025
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
Moderate
CVE-2025-6211
was published
for
llama-index
(pip)
Jul 10, 2025
n8n is vulnerable to Improper Authorization through its `/stop` endpoint
Moderate
CVE-2025-52554
was published
for
n8n
(npm)
Jul 3, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53664
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53665
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
ProTip!
Advisories are also available from the
GraphQL API