GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,934 advisories
Filter by severity
zkVM Underconstrained Vulnerability
Low
CVE-2025-52484
was published
for
risc0-circuit-rv32im
(Rust)
Jun 20, 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
Critical
CVE-2025-49132
was published
for
pterodactyl/panel
(Composer)
Jun 19, 2025
PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion
Low
CVE-2025-48059
was published
for
com.powsybl:powsybl-contingency-api
(Maven)
Jun 19, 2025
Arbitrary file read vulnerability in Jenkins Log Command Plugin
High
CVE-2024-23904
was published
for
org.jenkins-ci.plugins:log-command
(Maven)
Jan 24, 2024
Spring Framework server Web DoS Vulnerability
High
CVE-2024-22233
was published
for
org.springframework:spring-core
(Maven)
Jan 22, 2024
Sandbox escape in Artemis Java Test Sandbox
High
CVE-2024-23682
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
Inefficient Algorithmic Complexity in com.upokecenter:cbor
High
CVE-2024-23684
was published
for
com.upokecenter:cbor
(Maven)
Jan 19, 2024
Remote Code Execution vulnerability in Apache IoTDB via UDF
High
CVE-2023-46226
was published
for
apache-iotdb
(Maven)
Jan 15, 2024
Ackites KillWxapkg vulnerable to OS Command Injection
Low
CVE-2025-5030
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
Withdrawn Advisory: Lunary Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2024-6862
was published
for
@lunary/backend
(npm)
Sep 13, 2024
•
withdrawn
Withdrawn Advisory: lunary-ai/lunary XSS in SAML metadata endpoint
High
CVE-2024-5478
was published
for
lunary
(npm)
Jun 6, 2024
•
withdrawn
Withdrawn Advisory: Lunary information disclosure vulnerability
Moderate
CVE-2024-6867
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
Withdrawn Advisory: Lunary improper access control vulnerability
High
CVE-2024-6087
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+
High
GHSA-7cjh-xx4r-qh3f
was published
for
io.sentry:sentry-android
(Maven)
Jun 20, 2025
rfc3161-client has insufficient verification for timestamp response signatures
Critical
GHSA-6qhv-4h7r-2g9m
was published
for
rfc3161-client
(pip)
Jun 20, 2025
Mattermost allows an unauthorized Guest user access to Playbook
Moderate
CVE-2025-3228
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows unauthorized channel member management through playbook runs
Moderate
CVE-2025-3227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Pingora has a Request Smuggling Vulnerability
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
Jun 20, 2025
Duplicate Advisory: Pingora Request Smuggling and Cache Poisoning
High
GHSA-3qmp-g57h-rxf2
was published
for
pingora-core
(Rust)
May 22, 2025
•
withdrawn
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM possibly allows bypass of IP Filters
High
CVE-2025-52487
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Moderate
CVE-2025-52486
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Moderate
CVE-2025-52485
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
HaxCMS-PHP Command Injection Vulnerability
High
CVE-2025-49141
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
Mattermost allows authenticated users to write files to arbitrary locations
Critical
CVE-2025-4981
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
ProTip!
Advisories are also available from the
GraphQL API