GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,747
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,061 advisories
Filter by severity
Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler
Moderate
CVE-2023-27592
was published
for
miniflux.app/v2
(Go)
Apr 2, 2025
Go-Guerrilla SMTP Daemon allows the PROXY command to be sent multiple times
Moderate
CVE-2025-31135
was published
for
github.com/phires/go-guerrilla
(Go)
Apr 1, 2025
go.rgst.io/stencil/v2 vulnerable to Path Traversal
Moderate
GHSA-p799-q2pr-6mxj
was published
for
go.rgst.io/stencil/v2
(Go)
Mar 29, 2025
github.com/jaredallard/archives Has Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Moderate
GHSA-j95m-rcjp-q69h
was published
for
github.com/jaredallard/archives
(Go)
Mar 28, 2025
ingress-nginx controller - auth secret file path traversal vulnerability
Moderate
CVE-2025-24513
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
Kyverno ignores subjectRegExp and IssuerRegExp
Moderate
CVE-2025-29778
was published
for
github.com/kyverno/kyverno
(Go)
Mar 24, 2025
Envoy crashes when HTTP ext_proc processes local replies
Moderate
CVE-2025-30157
was published
for
github.com/envoyproxy/envoy
(Go)
Mar 21, 2025
Mattermost Fails to Enforce Certain Search APIs
Moderate
CVE-2025-30179
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public
Moderate
CVE-2025-27933
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
Moderate
CVE-2025-24920
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels
Moderate
CVE-2025-25274
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
OWASP Coraza WAF has parser confusion which leads to wrong URI in `REQUEST_FILENAME`
Moderate
CVE-2025-29914
was published
for
github.com/corazawaf/coraza/v3
(Go)
Mar 20, 2025
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
Moderate
CVE-2024-9900
was published
for
github.com/mudler/LocalAI
(Go)
Mar 20, 2025
OpenShift Console Has a Path Traversal Vulnerability
Moderate
CVE-2024-7631
was published
for
github.com/openshift/console
(Go)
Mar 19, 2025
OpenShift Hive Has an Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2024-25132
was published
for
github.com/openshift/hive
(Go)
Mar 19, 2025
Mattermost Fails to Properly Perform Viewer Role Authorization
Moderate
CVE-2025-1472
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 19, 2025
buildx allows a possible credential leakage to telemetry endpoint
Moderate
CVE-2025-0495
was published
for
github.com/docker/buildx
(Go)
Mar 17, 2025
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
Moderate
CVE-2025-29781
was published
for
github.com/metal3-io/baremetal-operator/apis
(Go)
Mar 17, 2025
containerd has an integer overflow in User ID handling
Moderate
CVE-2024-40635
was published
for
github.com/containerd/containerd
(Go)
Mar 17, 2025
onos-lib-go allows an index out-of-range panic
Moderate
CVE-2025-30077
was published
for
github.com/onosproject/onos-lib-go
(Go)
Mar 16, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Moderate
CVE-2024-9042
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Moderate
CVE-2025-1767
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
Moderate
CVE-2025-22870
was published
for
golang.org/x/net
(Go)
Mar 12, 2025
Duplicate Advisory: Plenti - Code Injection - Denial of Services
Moderate
GHSA-323w-6p85-26fr
was published
for
github.com/plentico/plenti
(Go)
Mar 12, 2025
•
withdrawn
LF Edge eKuiper allows Stored XSS in Rules Functionality
Moderate
CVE-2024-52812
was published
for
github.com/lf-edge/ekuiper
(Go)
Mar 10, 2025
ProTip!
Advisories are also available from the
GraphQL API