GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,295 advisories
Filter by severity
jquery-validation vulnerable to Cross-site Scripting
Moderate
CVE-2025-3573
was published
for
jquery-validation
(npm)
Apr 15, 2025
http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
Moderate
CVE-2025-32997
was published
for
http-proxy-middleware
(npm)
Apr 15, 2025
http-proxy-middleware can call writeBody twice because "else if" is not used
Moderate
CVE-2025-32996
was published
for
http-proxy-middleware
(npm)
Apr 15, 2025
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
Moderate
CVE-2025-32388
was published
for
@sveltejs/kit
(npm)
Apr 14, 2025
Directus inserts access token from query string into logs
Moderate
CVE-2024-47822
was published
for
@directus/api
(npm)
Apr 14, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Moderate
CVE-2025-32379
was published
for
koa
(npm)
Apr 9, 2025
ts-asn1-der has Incorrect DER Encoding of Numbers Leading to Denial of Service and Incorrect Value Representation
Moderate
CVE-2025-32029
was published
for
@apeleghq/asn1-der
(npm)
Apr 7, 2025
estree-util-value-to-estree allows prototype pollution in generated ESTree
Moderate
CVE-2025-32014
was published
for
estree-util-value-to-estree
(npm)
Apr 7, 2025
FlowiseDB vulnerable to SQL Injection by authenticated users
Moderate
GHSA-9c4c-g95m-c8cp
was published
for
flowise
(npm)
Apr 7, 2025
tarteaucitron.js allows url scheme injection via unfiltered inputs
Moderate
CVE-2025-31476
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
tarteaucitron.js allows prototype pollution via custom text injection
Moderate
CVE-2025-31475
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
tarteaucitron.js allows UI manipulation via unrestricted CSS injection
Moderate
CVE-2025-31138
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
expand-object Vulnerable to Prototype Pollution via the expand() Function
Moderate
CVE-2025-3197
was published
for
expand-object
(npm)
Apr 4, 2025
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-929m-phjg-qwcc
was published
for
mathlive
(npm)
Apr 1, 2025
•
withdrawn
aws-cdk-lib has Insertion of Sensitive Information into Log File vulnerability when using Cognito UserPoolClient Construct
Moderate
GHSA-qq4x-c6h6-rfxh
was published
for
aws-cdk-lib
(npm)
Mar 31, 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Moderate
CVE-2025-31125
was published
for
vite
(npm)
Mar 31, 2025
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-26042
was published
for
uptime-kuma
(npm)
Mar 31, 2025
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Moderate
CVE-2025-27793
was published
for
vega
(npm)
Mar 27, 2025
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter
Moderate
CVE-2025-26619
was published
for
vega
(npm)
Mar 27, 2025
Directus `search` query parameter allows enumeration of non permitted fields
Moderate
CVE-2025-30352
was published
for
directus
(npm)
Mar 26, 2025
Directus's S3 assets become unavailable after a burst of HEAD requests
Moderate
CVE-2025-30350
was published
for
@directus/storage-driver-s3
(npm)
Mar 26, 2025
Directus's S3 assets become unavailable after a burst of malformed transformations
Moderate
CVE-2025-30225
was published
for
@directus/storage-driver-s3
(npm)
Mar 26, 2025
ProTip!
Advisories are also available from the
GraphQL API