GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,395
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,252 advisories
Filter by severity
Chall-Manager's scenario decoding process does not check for zip bombs
High
CVE-2025-53633
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Chall-Manager is vulnerable to Path Traversal when extracting/decoding a zip archive
High
CVE-2025-53632
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
@pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation
Moderate
CVE-2025-53626
was published
for
@pdfme/common
(npm)
Jul 10, 2025
Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation
Moderate
CVE-2025-53549
was published
for
matrix-sdk
(Rust)
Jul 10, 2025
Parse Server exposes the data schema via GraphQL API
Moderate
CVE-2025-53364
was published
for
parse-server
(npm)
Jul 10, 2025
Keycloak vulnerable to phishing attacks through its Review Profile section
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
Moderate
CVE-2025-6211
was published
for
llama-index
(pip)
Jul 10, 2025
DynamicPageList3 vulnerability exposes hidden/suppressed usernames
High
CVE-2025-53625
was published
for
universal-omega/dynamic-page-list3
(Composer)
Jul 10, 2025
docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token
Critical
CVE-2025-53624
was published
for
docusaurus-plugin-content-gists
(npm)
Jul 9, 2025
Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form
Moderate
CVE-2025-53743
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Jenkins Xooa Plugin vulnerability does not mask its Xooa Deployment Token
Moderate
CVE-2025-53677
was published
for
io.jenkins.plugins:xooa
(Maven)
Jul 9, 2025
Jenkins Warrior Framework Plugin vulnerability exposes unencrypted passwords to certain authenticated users
Moderate
CVE-2025-53675
was published
for
org.jenkins-ci.plugins:warrior
(Maven)
Jul 9, 2025
Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53742
was published
for
org.jenkins-ci.plugins:pplitools-eyes
(Maven)
Jul 9, 2025
Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
Low
CVE-2025-53678
was published
for
io.jenkins.plugins:user1st-utester
(Maven)
Jul 9, 2025
Jenkins Xooa Plugin vulnerability exposes unencrypted tokens to authenticated users
Moderate
CVE-2025-53676
was published
for
io.jenkins.plugins:xooa
(Maven)
Jul 9, 2025
Jenkins VAddy Plugin vulnerability exposes plaintext keys on its job configuration form
Moderate
CVE-2025-53669
was published
for
org.jenkins-ci.plugins:vaddy-plugin
(Maven)
Jul 9, 2025
Jenkins Statistics Gatherer Plugin does not mask AWS Secret Key
Moderate
CVE-2025-53655
was published
for
org.jenkins.plugins.statistics.gatherer:statistics-gatherer
(Maven)
Jul 9, 2025
Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
Moderate
CVE-2025-53666
was published
for
org.jenkins-ci.plugins:deadmanssnitch
(Maven)
Jul 9, 2025
Jenkins VAddy Plugin vulnerability exposes unencrypted keys to certain authenticated users
Moderate
CVE-2025-53668
was published
for
org.jenkins-ci.plugins:vaddy-plugin
(Maven)
Jul 9, 2025
Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
Moderate
CVE-2025-53664
was published
for
com.apica:ApicaLoadtest
(Maven)
Jul 9, 2025
Jenkins QMetry Test Management Plugin vulnerability exposes API keys
Moderate
CVE-2025-53660
was published
for
org.jenkins-ci.plugins:qmetry-test-management
(Maven)
Jul 9, 2025
Jenkins Kryptowire Plugin vulnerability stores unencrypted Kryptowire API key
Moderate
CVE-2025-53672
was published
for
io.jenkins.plugins:kryptowire
(Maven)
Jul 9, 2025
Jenkins Nouvola DiveCloud Plugin vulnerability stores unencrypted credentials
Moderate
CVE-2025-53670
was published
for
org.jenkins-ci.plugins:nouvola-divecloud
(Maven)
Jul 9, 2025
Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens in its global configuration file
Moderate
CVE-2025-53673
was published
for
org.jenkins-ci.plugins:sensedia-api-platform
(Maven)
Jul 9, 2025
Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form
Moderate
CVE-2025-53671
was published
for
org.jenkins-ci.plugins:nouvola-divecloud
(Maven)
Jul 9, 2025
ProTip!
Advisories are also available from the
GraphQL API