GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,318
Maven
5,000+
npm
3,950
NuGet
711
pip
3,730
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,990 advisories
Filter by severity
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Moderate
CVE-2025-32788
was published
for
octoprint
(pip)
Apr 22, 2025
Harden-Runner allows evasion of 'disable-sudo' policy
Moderate
CVE-2025-32955
was published
for
step-security/harden-runner
(GitHub Actions)
Apr 22, 2025
Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Moderate
CVE-2025-32963
was published
for
github.com/minio/operator
(Go)
Apr 21, 2025
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
Moderate
CVE-2025-32793
was published
for
github.com/cilium/cilium
(Go)
Apr 21, 2025
OpenCMS cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-41446
was published
for
org.opencms:opencms-core
(Maven)
Apr 21, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
GoBGP crashes in the flowspec parser
Moderate
CVE-2025-43972
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP does not verify that the input length
Moderate
CVE-2025-43973
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP does not properly check the input length
Moderate
CVE-2025-43970
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
QMarkdown Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-43954
was published
for
@quasar/quasar-ui-qmarkdown
(npm)
Apr 20, 2025
one-api Cross-site Scripting vulnerability
Moderate
CVE-2025-3801
was published
for
github.com/songquanpeng/one-api
(Go)
Apr 19, 2025
Alkacon OpenCMS stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-41447
was published
for
org.opencms:opencms-core
(Maven)
Apr 18, 2025
Rasa Pro Missing Authentication For Voice Connector APIs
Moderate
CVE-2025-32377
was published
for
rasa-pro
(pip)
Apr 17, 2025
Liferay Cross-site Scripting vulnerability
Moderate
CVE-2025-3760
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Apr 17, 2025
PEAR HTTP_Request2 vulnerable to Cross-site Scripting
Moderate
CVE-2025-43717
was published
for
pear/http_request2
(Composer)
Apr 17, 2025
PyTorch Improper Resource Shutdown or Release vulnerability
Moderate
CVE-2025-3730
was published
for
torch
(pip)
Apr 16, 2025
golang.org/x/net vulnerable to Cross-site Scripting
Moderate
CVE-2025-22872
was published
for
golang.org/x/net
(Go)
Apr 16, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-2564
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Permission policy information leakage in Backstage permission system
Moderate
CVE-2025-32791
was published
for
@backstage/plugin-permission-backend
(npm)
Apr 16, 2025
Unregistered users can see "public" messages from a closed wiki via notifications from a different wiki
Moderate
CVE-2025-32783
was published
for
org.xwiki.platform:xwiki-platform-messagestream
(Maven)
Apr 16, 2025
Mattermost vulnerable to Observable Timing Discrepancy
Moderate
CVE-2025-27936
was published
for
github.com/mattermost/mattermost-plugin-msteams
(Go)
Apr 16, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-27571
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
vLLM vulnerable to Denial of Service by abusing xgrammar cache
Moderate
GHSA-hf3c-wxg2-49q9
was published
for
vllm
(pip)
Apr 15, 2025
jquery-validation vulnerable to Cross-site Scripting
Moderate
CVE-2025-3573
was published
for
jquery-validation
(npm)
Apr 15, 2025
ProTip!
Advisories are also available from the
GraphQL API