GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,987 advisories
Filter by severity
Rack session gets restored after deletion
Moderate
CVE-2025-46336
was published
for
rack-session
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-32441
was published
for
rack
(RubyGems)
May 8, 2025
Django has a denial-of-service possibility in strip_tags()
Moderate
CVE-2025-32873
was published
for
Django
(pip)
May 8, 2025
Craft CMS stores arbitrary content provided by unauthenticated users in session files
Moderate
CVE-2025-35939
was published
for
craftcms/cms
(Composer)
May 8, 2025
Koillection Cross Site Scripting vulnerability
Moderate
CVE-2025-29746
was published
for
koillection/koillection
(Composer)
May 7, 2025
JRuby-OpenSSL has hostname verification disabled by default
Moderate
CVE-2025-46551
was published
for
org.jruby:jruby
(Maven)
May 7, 2025
Easy!Appointments Denial of Service (DoS)
Moderate
CVE-2025-29448
was published
for
alextselegidis/easyappointments
(Composer)
May 7, 2025
Mithril snapshots for Cardano database could be compromised by an adversary
Moderate
GHSA-qv97-5qr8-2266
was published
for
mithril-client
(Rust)
May 7, 2025
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Moderate
CVE-2025-27533
was published
for
org.apache.activemq:activemq-client
(Maven)
May 7, 2025
HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store
Moderate
CVE-2025-2901
was published
for
org.jboss.hal:hal-console
(Maven)
May 6, 2025
Liferay Portal Reflected XSS in marketplace-app-manager-web
Moderate
CVE-2025-4388
was published
for
com.liferay:com.liferay.marketplace.app.manager.web
(Maven)
May 6, 2025
tanton_engine has unsound public API
Moderate
GHSA-m2xr-2vj4-wh94
was published
for
tanton_engine
(Rust)
May 6, 2025
@misskey-dev/summaly allows IP Filter Bypass via Redirect
Moderate
GHSA-jqx4-9gpq-rppm
was published
for
@misskey-dev/summaly
(npm)
May 6, 2025
Umbraco Makes User Enumeration Feasible Based on Timing of Login Response
Moderate
CVE-2025-46736
was published
for
Umbraco.Cms
(NuGet)
May 6, 2025
Inspektor Gadget Security Policies Can be Bypassed
Moderate
GHSA-pv22-fqcj-7xwh
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
May 6, 2025
Mezzanine CMS Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-29573
was published
for
Mezzanine
(pip)
May 5, 2025
league/commonmark contains a XSS vulnerability in Attributes extension
Moderate
CVE-2025-46734
was published
for
league/commonmark
(Composer)
May 5, 2025
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Moderate
CVE-2025-46730
was published
for
mobsf
(pip)
May 5, 2025
Linkerd resource exhaustion vulnerability
Moderate
CVE-2025-43915
was published
for
github.com/linkerd/linkerd2
(Go)
May 5, 2025
Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
Moderate
CVE-2025-46335
was published
for
mobsf
(pip)
May 5, 2025
Grokability Snipe-IT has incorrect authorization for accessing asset information
Moderate
CVE-2025-47226
was published
for
snipe/snipe-it
(Composer)
May 2, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization
Moderate
CVE-2025-3879
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
Moderate
CVE-2025-4210
was published
for
github.com/casdoor/casdoor
(Go)
May 2, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-4166
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
ProTip!
Advisories are also available from the
GraphQL API