GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
8,012 advisories
Filter by severity
org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
High
CVE-2025-32968
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 23, 2025
Infinite loop condition in Amazon.IonDotnet
High
CVE-2025-3857
was published
for
Amazon.IonDotnet
(NuGet)
Apr 21, 2025
Traefik has a possible vulnerability with the path matchers
High
CVE-2025-32431
was published
for
github.com/traefik/traefik
(Go)
Apr 21, 2025
GoBGP panics due to a zero value for softwareVersionLen
High
CVE-2025-43971
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
youtube-dl vulnerable to file system modification and RCE through improper file-extension sanitization
High
GHSA-22fp-mf44-f2mq
was published
for
youtube-dl
(pip)
Apr 18, 2025
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
High
CVE-2025-22868
was published
for
github.com/traefik/traefik/v2
(Go)
Apr 18, 2025
ses's global contour bindings leak into Compartment lexical scope
High
CVE-2025-32792
was published
for
ses
(npm)
Apr 18, 2025
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
High
CVE-2025-32442
was published
for
fastify
(npm)
Apr 18, 2025
Pycel allows code injection via a crafted formula
High
CVE-2024-53924
was published
for
pycel
(pip)
Apr 17, 2025
OpenMetadata SQL Injection
High
CVE-2024-55238
was published
for
org.open-metadata:openmetadata-service
(Maven)
Apr 17, 2025
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
High
CVE-2024-53305
was published
for
whoogle-search
(pip)
Apr 16, 2025
Kyverno vulnerable to SSRF via Service Calls
High
GHSA-459x-q9hg-4gpq
was published
for
github.com/kyverno/kyverno
(Go)
Apr 15, 2025
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
High
CVE-2025-3445
was published
for
github.com/mholt/archiver
(Go)
Apr 14, 2025
CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows
High
GHSA-f87w-3j5w-v58p
was published
for
CefSharp.OffScreen
(NuGet)
Apr 12, 2025
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
High
CVE-2025-22869
was published
for
golang.org/x/crypto
(Go)
Apr 12, 2025
SurrealDB CPU exhaustion via custom functions result in total DoS
High
GHSA-pxw4-94j3-v9pf
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
High
GHSA-3633-g6mg-p6qq
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
High
GHSA-rq86-9m6r-cm3g
was published
for
surrealdb
(Rust)
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
GHSA-6jrf-4jv4-r9mw
was published
for
tendermint-light-client-verifier
(Rust)
Apr 9, 2025
crud-query-parser SQL Injection vulnerability
High
CVE-2025-32020
was published
for
crud-query-parser
(npm)
Apr 9, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Flowise Vulnerable to SQL Injection via `tableName` Parameter
High
CVE-2025-29189
was published
for
flowise-components
(npm)
Apr 9, 2025
Joomla CMS Multi-Factor Authentication Bypass
High
CVE-2025-25227
was published
for
joomla/joomla-cms
(Composer)
Apr 8, 2025
ProTip!
Advisories are also available from the
GraphQL API