GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,884
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,205
NuGet
743
pip
3,978
Pub
12
RubyGems
947
Rust
1,034
Swift
39
Unreviewed advisories
All unreviewed
5,000+
24,104 advisories
Filter by severity
Flowise Stored XSS vulnerability through logs in chatbot
Moderate
GHSA-7r4h-vmj9-wg42
was published
for
flowise
(npm)
Oct 3, 2025
Flowise vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
GHSA-964p-j4gg-mhwc
was published
for
flowise
(npm)
Oct 3, 2025
wrflib has a soundness issue and is unmaintained
Low
GHSA-466c-pfvv-v83g
was published
for
wrflib
(Rust)
Oct 3, 2025
phpMyFAQ duplicate email registration allows multiple accounts with the same email
High
CVE-2025-59943
was published
for
thorsten/phpmyfaq
(Composer)
Oct 3, 2025
Claude Code permission deny bypass through symlink
Low
CVE-2025-59829
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
Claude Code can execute commands prior to the startup trust dialog
High
CVE-2025-59536
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
High
CVE-2025-54286
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns
High
CVE-2025-54287
was published
for
github.com/lxc/lxd
(Go)
Oct 2, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API
High
CVE-2025-54289
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
Moderate
CVE-2025-54290
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Canonical LXD Project Existence Determination Through Error Handling in Image Get Function
Moderate
CVE-2025-54291
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
Low
CVE-2025-61677
was published
for
datachain
(pip)
Oct 2, 2025
Apache Kylin Authentication Bypass Vulnerability
High
CVE-2025-61733
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Apache Kylin Files or Directories Accessible to External Parties
High
CVE-2025-61734
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
High
CVE-2025-61735
was published
for
org.apache.kylin:kylin
(Maven)
Oct 2, 2025
Dolibarr vulnerable to RCE via the computed field parameter
High
CVE-2025-56588
was published
for
dolibarr/dolibarr
(Composer)
Oct 1, 2025
Django vulnerable to partial directory traversal via archives
Low
CVE-2025-59682
was published
for
django
(pip)
Oct 1, 2025
Django vulnerable to SQL injection in column aliases
High
CVE-2025-59681
was published
for
django
(pip)
Oct 1, 2025
Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-7jp2-5h22-m432
was published
for
auth0/symfony
(Composer)
Oct 1, 2025
Auth0 Wordpress plugin Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-w22c-pw5m-482x
was published
for
auth0/wordpress
(Composer)
Oct 1, 2025
laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-hjfh-5jmm-xr24
was published
for
auth0/login
(Composer)
Oct 1, 2025
ProTip!
Advisories are also available from the
GraphQL API