GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,809
Erlang
36
GitHub Actions
31
Go
2,395
Maven
5,000+
npm
4,030
NuGet
720
pip
3,819
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,249 advisories
Filter by severity
Axios has Transitive Critical Vulnerability via form-data — Predictable Boundary Values (CVE-2025-7783)
High
GHSA-rm8p-cx58-hcvx
was published
for
axios
(npm)
Jul 23, 2025
Possible ORM Leak Vulnerability in the Harbor
Moderate
CVE-2025-30086
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
FastAPI Guard has a regex bypass
High
CVE-2025-54365
was published
for
fastapi-guard
(pip)
Jul 23, 2025
Harbor repository description page has Cross-site Scripting vulnerability
Moderate
CVE-2025-32019
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
private-ip vulnerable to Server-Side Request Forgery
High
CVE-2025-8020
was published
for
private-ip
(npm)
Jul 23, 2025
files-bucket-server vulnerable to Directory Traversal
High
CVE-2025-8021
was published
for
files-bucket-server
(npm)
Jul 23, 2025
Ollama vulnerable to Cross-Domain Token Exposure
Moderate
CVE-2025-51471
was published
for
github.com/ollama/ollama
(Go)
Jul 22, 2025
Aim vulnerable to Cross-site Scripting
Moderate
CVE-2025-51464
was published
for
aim
(pip)
Jul 22, 2025
Dagster Local File Inclusion vulnerability
Moderate
CVE-2025-51481
was published
for
dagster
(pip)
Jul 22, 2025
Authentik has insufficient check for account active status when authenticating with OAuth/SAML Sources
High
CVE-2025-53942
was published
for
goauthentik.io
(Go)
Jul 22, 2025
Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service
High
CVE-2025-47281
was published
for
github.com/kyverno/kyverno
(Go)
Jul 22, 2025
Powermail extension for TYPO3 allows Insecure Direct Object Reference
Moderate
CVE-2025-7899
was published
for
in2code/powermail
(Composer)
Jul 22, 2025
Femanager extension for TYPO3 allows Insecure Direct Object Reference
Moderate
CVE-2025-7900
was published
for
in2code/femanager
(Composer)
Jul 22, 2025
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
High
CVE-2025-54140
was published
for
pyload-ng
(pip)
Jul 21, 2025
HAX CMS application pages vulnerable to clickjacking
Moderate
CVE-2025-54139
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 21, 2025
LibreNMS has Authenticated Remote File Inclusion in ajax_form.php that Allows RCE
High
CVE-2025-54138
was published
for
librenms/librenms
(Composer)
Jul 21, 2025
NodeJS version of the HAX CMS application is distributed with Default Secrets
High
CVE-2025-54137
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
High
CVE-2025-54128
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Nokogiri patches vendored libxml2 to resolve multiple CVEs
Critical
GHSA-353f-x4gh-cqq8
was published
for
nokogiri
(RubyGems)
Jul 21, 2025
Starlette has possible denial-of-service vector when parsing large files in multipart forms
Moderate
CVE-2025-54121
was published
for
starlette
(pip)
Jul 21, 2025
Dolibarr has Remote Code Execution Vulnerability (Bypass)
High
GHSA-49xw-hw94-fmv2
was published
for
dolibarr/dolibarr
(Composer)
Jul 21, 2025
RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs
High
GHSA-c5qx-p38x-qf5w
was published
for
RageAgainstThePixel/setup-steamcmd
(GitHub Actions)
Jul 21, 2025
ProTip!
Advisories are also available from the
GraphQL API