GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
8,012 advisories
Filter by severity
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
Navidrome Transcoding Permission Bypass Vulnerability Report
High
CVE-2025-48948
was published
for
github.com/navidrome/navidrome
(Go)
May 29, 2025
Navidrome allows SQL Injection via role parameter
High
CVE-2025-48949
was published
for
github.com/navidrome/navidrome
(Go)
May 29, 2025
PHPOffice Math allows XXE when processing an XML file in the MathML format
High
CVE-2025-48882
was published
for
phpoffice/math
(Composer)
May 29, 2025
Arrow2 allows out of bounds access in public safe API
High
GHSA-wv8j-m3hx-924j
was published
for
arrow2
(Rust)
May 30, 2025
Moodle SSRF Vulnerability
High
CVE-2019-6970
was published
for
moodle/moodle
(Composer)
May 14, 2022
Exposure of sensitive information in ClickHouse
High
CVE-2024-23689
was published
for
com.clickhouse:clickhouse-client
(Maven)
Jan 19, 2024
WEBRick vulnerable to HTTP Request/Response Smuggling
High
CVE-2020-25613
was published
for
webrick
(RubyGems)
May 24, 2022
Duplicate Advisory: Bundled libwebp in Pillow vulnerable
High
GHSA-56pw-mpj4-fxww
was published
for
pillow
(pip)
Oct 5, 2023
•
withdrawn
ZITADEL Allows Account Takeover via Malicious X-Forwarded-Proto Header Injection
High
CVE-2025-48936
was published
for
github.com/zitadel/zitadel
(Go)
May 28, 2025
Apache Superset: Improper authorization bypass on row level security via SQL Injection
High
CVE-2025-48912
was published
for
apache-superset
(pip)
May 30, 2025
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
High
CVE-2025-41235
was published
for
org.springframework.cloud:spring-cloud-gateway-server
(Maven)
May 30, 2025
Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
High
CVE-2025-48881
was published
for
com.ritense.valtimo:object-management
(Maven)
May 28, 2025
MantisBT CSV Injection unprivileged user access in csv_export.php
High
CVE-2021-43257
was published
for
mantisbt/mantisbt
(Composer)
Apr 15, 2022
MantisBT Incorrect Authorization for bug_revision_view_page.php check
High
CVE-2020-35849
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
Missing permission checks on Hazelcast client protocol
High
CVE-2023-45859
was published
for
com.hazelcast:hazelcast
(Maven)
Feb 27, 2024
XStream is vulnerable to a Remote Command Execution attack
High
CVE-2021-29505
was published
for
com.thoughtworks.xstream:xstream
(Maven)
May 18, 2021
Unsafe deserialization in SmtpTransport in CakePHP
High
CVE-2019-11458
was published
for
cakephp/cakephp
(Composer)
Dec 2, 2019
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
High
CVE-2025-32442
was published
for
fastify
(npm)
Apr 18, 2025
Apache CXF TLS hostname verification does not work correctly with com.sun.net.ssl.*
High
CVE-2018-8039
was published
for
org.apache.cxf:apache-cxf
(Maven)
Oct 19, 2018
MantisBT Remote Code Execution
High
CVE-2019-15715
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
Tornado vulnerable to excessive logging caused by malformed multipart form data
High
CVE-2025-47287
was published
for
tornado
(pip)
May 16, 2025
MantisBT Insufficient Session Experation allows for credential theft
High
CVE-2009-20001
was published
for
mantisbt/mantisbt
(Composer)
Apr 21, 2022
ProTip!
Advisories are also available from the
GraphQL API