GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,396
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,396 advisories
Filter by severity
eKuiper API endpoints handling SQL queries with user-controlled table names.
High
CVE-2025-54379
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Jul 24, 2025
Possible ORM Leak Vulnerability in the Harbor
Moderate
CVE-2025-30086
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
Harbor repository description page has Cross-site Scripting vulnerability
Moderate
CVE-2025-32019
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
Ollama vulnerable to Cross-Domain Token Exposure
Moderate
CVE-2025-51471
was published
for
github.com/ollama/ollama
(Go)
Jul 22, 2025
Authentik has insufficient check for account active status when authenticating with OAuth/SAML Sources
High
CVE-2025-53942
was published
for
goauthentik.io
(Go)
Jul 22, 2025
Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service
High
CVE-2025-47281
was published
for
github.com/kyverno/kyverno
(Go)
Jul 22, 2025
melange's world-writable permissions expose SBOM files to potential image tampering
Moderate
CVE-2025-54059
was published
for
chainguard.dev/melange
(Go)
Jul 18, 2025
apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files
High
CVE-2025-53945
was published
for
chainguard.dev/apko
(Go)
Jul 18, 2025
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
High
CVE-2025-22868
was published
for
golang.org/x/oauth2
(Go)
Jul 18, 2025
Mattermost has Insufficiently Protected Credentials
Low
CVE-2025-6227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Mattermost Path Traversal vulnerability
Moderate
CVE-2025-6233
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Mattermost Missing Authentication for Critical Function
Moderate
CVE-2025-6226
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Grafana is vulnerable to XSS attacks through open redirects and path traversal
High
CVE-2025-6023
was published
for
github.com/grafana/grafana
(Go)
Jul 18, 2025
Grafana's insecure DingDing Alert integration exposes sensitive information
Moderate
CVE-2025-3415
was published
for
github.com/grafana/grafana
(Go)
Jul 17, 2025
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
High
CVE-2025-53893
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout
High
CVE-2025-53634
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Chall-Manager's scenario decoding process does not check for zip bombs
High
CVE-2025-53633
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Chall-Manager is vulnerable to Path Traversal when extracting/decoding a zip archive
High
CVE-2025-53632
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
Low
GHSA-phhq-63jg-fp7r
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 9, 2025
Juju allows arbitrary executable uploads via authenticated endpoint without authorization
High
CVE-2025-0928
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorization
Moderate
CVE-2025-53512
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Juju zip slip vulnerability via authenticated endpoint
High
CVE-2025-53513
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Cosmos SDK's Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt
High
GHSA-p22h-3m2v-cmgh
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jul 8, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content
High
CVE-2025-53547
was published
for
helm.sh/helm/v3
(Go)
Jul 8, 2025
ProTip!
Advisories are also available from the
GraphQL API