GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,987 advisories
Filter by severity
@cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
CVE-2025-4144
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
@cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
CVE-2025-4143
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
GHSA-vh4h-fvqf-q9wv
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Duplicate Advisory: @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
GHSA-7cp4-jw97-3rc2
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Panic in mp3-metadata due to the lack of bounds checking
Moderate
GHSA-927q-g9w9-pm54
was published
for
mp3-metadata
(Rust)
Apr 30, 2025
Vite's server.fs.deny bypassed with /. for files under project root
Moderate
CVE-2025-46565
was published
for
vite
(npm)
Apr 30, 2025
Keycloak vulnerable to two factor authentication bypass
Moderate
CVE-2025-3910
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
Moderate
CVE-2025-46554
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Apr 30, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-46331
was published
for
github.com/openfga/openfga
(Go)
Apr 30, 2025
Duplicate Advisory: Keycloak vulnerable to two factor authentication bypass
Moderate
GHSA-fx44-2wx5-5fvp
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 29, 2025
•
withdrawn
Auth0 NextJS SDK v4 Missing Session Invalidation
Moderate
CVE-2025-46344
was published
for
@auth0/nextjs-auth0
(npm)
Apr 29, 2025
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
Moderate
CVE-2025-46560
was published
for
vllm
(pip)
Apr 29, 2025
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Moderate
GHSA-wfm2-rq5g-f8v5
was published
for
@account-kit/smart-contracts
(npm)
Apr 29, 2025
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
Moderate
CVE-2025-46550
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
Moderate
CVE-2025-46549
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability
Moderate
CVE-2025-32970
was published
for
org.xwiki.platform:xwiki-platform-wysiwyg-api
(Maven)
Apr 29, 2025
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Moderate
CVE-2025-1194
was published
for
transformers
(pip)
Apr 29, 2025
Apache Tomcat Denial of Service via invalid HTTP priority header
Moderate
CVE-2025-31650
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
n8n Vulnerable to Stored XSS through Attachments View Endpoint
Moderate
CVE-2025-46343
was published
for
n8n
(npm)
Apr 28, 2025
net-imap rubygem vulnerable to possible DoS by memory exhaustion
Moderate
CVE-2025-43857
was published
for
net-imap
(RubyGems)
Apr 28, 2025
Apereo CAS has inefficient regular expression complexity
Moderate
CVE-2025-3986
was published
for
org.apereo.cas:cas-server-core-configuration-metadata-repository
(Maven)
Apr 27, 2025
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
Moderate
CVE-2025-3640
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
Moderate
CVE-2025-3636
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
ProTip!
Advisories are also available from the
GraphQL API