GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,749
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
8,021 advisories
Filter by severity
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
High
CVE-2024-55658
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
SiYuan has an arbitrary file read via /api/template/render
High
CVE-2024-55657
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
Podman's incorrect handling of the supplementary groups may lead to data disclosure, modification
High
CVE-2022-2989
was published
for
github.com/containers/podman/v3
(Go)
Sep 14, 2022
Fluent Fluentd and Fluent-ui use default password
High
CVE-2020-21514
was published
for
fluentd-ui
(RubyGems)
Apr 4, 2023
Multer vulnerable to Denial of Service via unhandled exception
High
CVE-2025-48997
was published
for
multer
(npm)
Jun 5, 2025
Grafana vulnerable to authenticated users bypassing dashboard, folder permissions
High
CVE-2025-3260
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
High
CVE-2025-48957
was published
for
astrbot
(pip)
Jun 4, 2025
NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
High
CVE-2025-48947
was published
for
@auth0/nextjs-auth0
(npm)
Jun 4, 2025
Deno's AES GCM authentication tags are not verified
High
CVE-2025-24015
was published
for
deno
(Rust)
Jun 4, 2025
Arbitrary file read vulnerability in Git server Plugin can lead to RCE
High
CVE-2024-23899
was published
for
org.jenkins-ci.plugins:git-server
(Maven)
Jan 24, 2024
Apache Tomcat - Denial of Service
High
CVE-2024-34750
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jul 3, 2024
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
High
CVE-2024-45498
was published
for
apache-airflow
(pip)
Sep 7, 2024
Apache Linkis vulnerable to privilege escalation
High
CVE-2024-27181
was published
for
org.apache.linkis:linkis
(Maven)
Aug 2, 2024
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2025-30167
was published
for
jupyter_core
(pip)
Jun 4, 2025
quic-go Has Panic in Path Probe Loss Recovery Handling
High
CVE-2025-29785
was published
for
github.com/quic-go/quic-go
(Go)
Jun 3, 2025
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
High
CVE-2025-48881
was published
for
com.ritense.valtimo:object-management
(Maven)
May 28, 2025
org.ini4j allows attackers to cause a Denial of Service (DoS)
High
CVE-2022-41404
was published
for
org.ini4j:ini4j
(Maven)
Oct 12, 2022
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55638
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55637
was published
for
drupal/core
(Composer)
Dec 10, 2024
Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters
High
CVE-2024-28123
was published
for
wasmi
(Rust)
Mar 7, 2024
kangax html-minifier REDoS vulnerability
High
CVE-2022-37620
was published
for
html-minifier
(npm)
Oct 31, 2022
Wildfly Elytron integration susceptible to brute force attacks via CLI
High
CVE-2025-23368
was published
for
org.wildfly.core:wildfly-elytron-integration
(Maven)
Mar 4, 2025
path-to-regexp contains a ReDoS
High
CVE-2024-52798
was published
for
path-to-regexp
(npm)
Dec 5, 2024
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
Apache Superset: Improper authorization bypass on row level security via SQL Injection
High
CVE-2025-48912
was published
for
apache-superset
(pip)
May 30, 2025
ProTip!
Advisories are also available from the
GraphQL API