GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,528 advisories
Filter by severity
Liferay Portal allows improper access through the expandoTableLocalService
Moderate
CVE-2025-43773
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.impl
(Maven)
Aug 29, 2025
webp crate may expose memory contents when encoding an image
Moderate
GHSA-9q78-27f3-2jmh
was published
for
webp
(Rust)
Aug 29, 2025
github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Moderate
CVE-2025-47909
was published
for
github.com/gorilla/csrf
(Go)
Aug 29, 2025
Eventlet affected by HTTP request smuggling in unparsed trailers
Moderate
CVE-2025-58068
was published
for
eventlet
(pip)
Aug 29, 2025
Google Sign-In for Rails allowed redirect to protocol-relative URI
Moderate
CVE-2025-58067
was published
for
google_sign_in
(RubyGems)
Aug 29, 2025
AiondaDotCom mcp-ssh command injection vulnerability in SSH operations
Moderate
CVE-2025-9654
was published
for
@aiondadotcom/mcp-ssh
(npm)
Aug 29, 2025
Payload does not invalidate JWTs after log out
Moderate
CVE-2025-4643
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
Payload's SQLite adapter Session Fixation vulnerability
Moderate
CVE-2025-4644
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
Moderate
CVE-2025-58058
was published
for
github.com/ulikunitz/xz
(Go)
Aug 28, 2025
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
Moderate
CVE-2025-58049
was published
for
org.xwiki.platform:xwiki-platform-export-pdf-api
(Maven)
Aug 28, 2025
Contao does not properly manage privileges for page and article fields
Moderate
CVE-2025-57759
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao can disclose sensitive information in the news module
Moderate
CVE-2025-57757
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao discloses sensitive information in the front end search index
Moderate
CVE-2025-57756
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao applies improper access control in the back end voters
Moderate
CVE-2025-57758
was published
for
contao/contao
(Composer)
Aug 28, 2025
lychee link checking action affected by arbitrary code injection in composite action
Moderate
CVE-2024-48908
was published
for
lycheeverse/lychee-action
(GitHub Actions)
Aug 28, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector has an insecure password storage vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
Google Sign-In for Rails allowed redirects to malformed URLs
Moderate
CVE-2025-57821
was published
for
google_sign_in
(RubyGems)
Aug 27, 2025
Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start
Moderate
GHSA-q77w-mwjj-7mqx
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python cProfile.run
Moderate
GHSA-49gj-c84q-6qm9
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python cProfile.runctx
Moderate
GHSA-9w88-8rmg-7g2p
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python doctest.debug_script
Moderate
GHSA-fqq6-7vqf-w3fg
was published
for
picklescan
(pip)
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API