GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,811
Erlang
36
GitHub Actions
32
Go
2,396
Maven
5,000+
npm
4,033
NuGet
721
pip
3,824
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,355 advisories
Filter by severity
tj-actions/branch-names has a Command Injection Vulnerability
Critical
GHSA-gq52-6phf-x2r6
was published
for
tj-actions/branch-names
(GitHub Actions)
Jul 25, 2025
Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
Critical
GHSA-75jv-vfxf-3865
was published
for
assemblyline-service-client
(pip)
Jul 25, 2025
Node-SAML SAML Authentication Bypass
Critical
CVE-2025-54369
was published
for
@node-saml/node-saml
(npm)
Jul 25, 2025
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
Critical
CVE-2025-32429
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jul 24, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Nokogiri patches vendored libxml2 to resolve multiple CVEs
Critical
GHSA-353f-x4gh-cqq8
was published
for
nokogiri
(RubyGems)
Jul 21, 2025
nova-tiptap has Unauthenticated Arbitrary File Upload Vulnerability
Critical
CVE-2025-54082
was published
for
manogi/nova-tiptap
(Composer)
Jul 21, 2025
form-data uses unsafe random function in form-data for choosing boundary
Critical
CVE-2025-7783
was published
for
form-data
(npm)
Jul 21, 2025
simogeo/filemanager arbitrary file upload vulnerability
Critical
CVE-2025-46001
was published
for
simogeo/filemanager
(Composer)
Jul 18, 2025
Livewire is vulnerable to remote command execution during component property update hydration
Critical
CVE-2025-54068
was published
for
livewire/livewire
(Composer)
Jul 17, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Critical
CVE-2025-53836
was published
for
org.xwiki.rendering:xwiki-rendering-transformation-macro
(Maven)
Jul 14, 2025
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
Critical
CVE-2025-53835
was published
for
org.xwiki.rendering:xwiki-rendering-syntax-xhtml
(Maven)
Jul 14, 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
Critical
CVE-2025-53833
was published
for
binarytorch/larecipe
(Composer)
Jul 14, 2025
docusaurus-plugin-content-gists vulnerability exposes GitHub Personal Access Token
Critical
CVE-2025-53624
was published
for
docusaurus-plugin-content-gists
(npm)
Jul 9, 2025
Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests
Critical
CVE-2025-53620
was published
for
@builder.io/qwik-city
(npm)
Jul 9, 2025
mcp-remote exposed to OS command injection via untrusted MCP server connections
Critical
CVE-2025-6514
was published
for
mcp-remote
(npm)
Jul 9, 2025
Conductor vulnerable to OS command injection through unrestricted access to Java classes
Critical
CVE-2025-26074
was published
for
org.conductoross:conductor-core
(Maven)
Jun 30, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Critical
CVE-2025-32897
was published
for
org.apache.seata:seata-config-core
(Maven)
Jun 28, 2025
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
Critical
CVE-2025-50213
was published
for
apache-airflow-providers-snowflake
(pip)
Jun 26, 2025
Gogs allows deletion of internal files which leads to remote command execution
Critical
CVE-2024-56731
was published
for
gogs.io/gogs
(Go)
Jun 24, 2025
pbkdf2 silently disregards Uint8Array input, returning static keys
Critical
CVE-2025-6547
was published
for
pbkdf2
(npm)
Jun 23, 2025
pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos
Critical
CVE-2025-6545
was published
for
pbkdf2
(npm)
Jun 23, 2025
rfc3161-client has insufficient verification for timestamp response signatures
Critical
CVE-2025-52556
was published
for
rfc3161-client
(pip)
Jun 20, 2025
Mattermost allows authenticated users to write files to arbitrary locations
Critical
CVE-2025-4981
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
ProTip!
Advisories are also available from the
GraphQL API