GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,396
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,030 advisories
Filter by severity
Withdrawn Advisory: Axios has Transitive Critical Vulnerability via form-data
High
CVE-2025-54371
was published
for
axios
(npm)
Jul 23, 2025
•
withdrawn
files-bucket-server vulnerable to Directory Traversal
High
CVE-2025-8021
was published
for
files-bucket-server
(npm)
Jul 23, 2025
private-ip vulnerable to Server-Side Request Forgery
High
CVE-2025-8020
was published
for
private-ip
(npm)
Jul 23, 2025
HAX CMS application pages vulnerable to clickjacking
Moderate
CVE-2025-54139
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 21, 2025
NodeJS version of the HAX CMS application is distributed with Default Secrets
High
CVE-2025-54137
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
High
CVE-2025-54128
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
form-data uses unsafe random function in form-data for choosing boundary
Critical
CVE-2025-7783
was published
for
form-data
(npm)
Jul 21, 2025
Alchemy Non-SMA and Webauthn Account Security Advisory
High
GHSA-56r6-ccm5-8hg3
was published
for
@account-kit/smart-contracts
(npm)
Jul 21, 2025
@translated/lara-mcp vulnerable to command injection in import_tmx tool
High
CVE-2025-53832
was published
for
@translated/lara-mcp
(npm)
Jul 21, 2025
Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
High
CVE-2025-54075
was published
for
@nuxtjs/mdc
(npm)
Jul 20, 2025
eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
High
CVE-2025-54313
was published
for
@pkgr/core
(npm)
Jul 19, 2025
@eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser
High
GHSA-xffm-g5w8-qvg7
was published
for
@eslint/plugin-kit
(npm)
Jul 18, 2025
OpenZeppelin Contracts Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers
Moderate
CVE-2025-54070
was published
for
@openzeppelin/contracts
(npm)
Jul 17, 2025
on-headers is vulnerable to http response header manipulation
Low
CVE-2025-7339
was published
for
on-headers
(npm)
Jul 17, 2025
Multer vulnerable to Denial of Service via unhandled exception from malformed request
High
CVE-2025-7338
was published
for
multer
(npm)
Jul 17, 2025
DiracX-Web is vulnerable to attack through an Open Redirect on its login page
Moderate
CVE-2025-54066
was published
for
@dirac-grid/diracx-web-components
(npm)
Jul 17, 2025
vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes
Moderate
CVE-2025-53892
was published
for
@intlify/core
(npm)
Jul 16, 2025
GitHub Kanban MCP Server vulnerable to Command Injection
High
CVE-2025-53818
was published
for
@sunwood-ai-labs/github-kanban-mcp-server
(npm)
Jul 15, 2025
Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
Moderate
CVE-2025-53889
was published
for
directus
(npm)
Jul 15, 2025
Directus' exact version number is exposed by the OpenAPI Spec
Moderate
CVE-2025-53887
was published
for
directus
(npm)
Jul 15, 2025
Directus tokens are not redacted in flow logs, exposing session credentials to all admin
Moderate
CVE-2025-53886
was published
for
directus
(npm)
Jul 15, 2025
Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged
Moderate
CVE-2025-53885
was published
for
directus
(npm)
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API