GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,952
Erlang
39
GitHub Actions
38
Go
2,612
Maven
5,000+
npm
4,252
NuGet
760
pip
4,027
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
10,885 advisories
Filter by severity
OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability
Moderate
GHSA-grjp-54v3-c442
was published
for
usd-core
(pip)
Oct 29, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
CKAN vulnerable to fixed session IDs
Moderate
CVE-2025-64100
was published
for
ckan
(pip)
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
Moderate
CVE-2025-64094
was published
for
DotNetNuke.Core
(NuGet)
Oct 29, 2025
DNN CKEditor Provider allows unauthenticated upload out-of-the-box
Moderate
CVE-2025-62802
was published
for
Dnn.Platform
(NuGet)
Oct 29, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Moderate
CVE-2025-62801
was published
for
fastmcp
(pip)
Oct 29, 2025
FastMCP vulnerable to reflected XSS in client's callback page
Moderate
CVE-2025-62800
was published
for
fastmcp
(pip)
Oct 29, 2025
CKAN vulnerable to stored XSS in resource description
Moderate
CVE-2025-54384
was published
for
ckan
(pip)
Oct 29, 2025
Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
Moderate
CVE-2025-64147
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
Moderate
CVE-2025-64149
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin is missing a permissions check
Moderate
CVE-2025-64150
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin is missing a permissions check
Moderate
CVE-2025-64148
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Moderate
CVE-2025-64132
was published
for
io.jenkins.plugins:mcp-server
(Maven)
Oct 29, 2025
Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64133
was published
for
jp.ikedam.jenkins.plugins:extensible-choice-parameter
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin does not mask API tokens displayed on the job configuration form
Moderate
CVE-2025-64145
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files
Moderate
CVE-2025-64144
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
Jenkins Curseforge Publisher Plugin stores API Keys unencrypted in job config.xml files
Moderate
CVE-2025-64146
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64138
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins OpenShift Pipeline Plugin stores authorization tokens unencrypted in job config.xml files
Moderate
CVE-2025-64143
was published
for
com.openshift.jenkins:openshift-pipeline
(Maven)
Oct 29, 2025
Jenkins Themis Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64136
was published
for
org.jenkins-ci.plugins:themis
(Maven)
Oct 29, 2025
Jenkins Eggplant Runner Plugin protection mechanism disabled
Moderate
CVE-2025-64135
was published
for
io.jenkins.plugins:eggplant-runner
(Maven)
Oct 29, 2025
Jenkins Nexus Task Runner Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64141
was published
for
org.jenkins-ci.plugins:nexus-task-runner
(Maven)
Oct 29, 2025
Jenkins Start Windocks Containers Plugin is missing a permission check
Moderate
CVE-2025-64139
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins Nexus Task Runner Plugin is missing a permission check
Moderate
CVE-2025-64142
was published
for
org.jenkins-ci.plugins:nexus-task-runner
(Maven)
Oct 29, 2025
Jenkins Themis Plugin is missing a permission check
Moderate
CVE-2025-64137
was published
for
org.jenkins-ci.plugins:themis
(Maven)
Oct 29, 2025
ProTip!
Advisories are also available from the
GraphQL API