GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,295 advisories
Filter by severity
Vite bypasses server.fs.deny when using ?raw??
Moderate
CVE-2025-30208
was published
for
vite
(npm)
Mar 25, 2025
GetmeUK ContentTools Cross-Site Scripting (XSS)
Moderate
CVE-2025-2699
was published
for
ContentTools
(npm)
Mar 24, 2025
AWS CDK CLI prints AWS credentials retrieved by custom credential plugins
Moderate
CVE-2025-2598
was published
for
aws-cdk
(npm)
Mar 21, 2025
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
Fast-JWT Improperly Validates iss Claims
Moderate
CVE-2025-30144
was published
for
fast-jwt
(npm)
Mar 19, 2025
Duplicate Advisory: Uptime Kuma ReDoS vulnerability
Moderate
GHSA-3rw8-4xrq-3f7p
was published
for
uptime-kuma
(npm)
Mar 17, 2025
•
withdrawn
JS Html Sanitizer allows XSS when used with contentEditable
Moderate
CVE-2025-29771
was published
for
@jitbit/htmlsanitizer
(npm)
Mar 14, 2025
nest allows a remote attacker to execute arbitrary code via the Content-Type header
Moderate
CVE-2024-29409
was published
for
@nestjs/common
(npm)
Mar 14, 2025
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
Moderate
CVE-2025-27789
was published
for
@babel/helpers
(npm)
Mar 11, 2025
NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page
Moderate
CVE-2025-27506
was published
for
nocodb
(npm)
Mar 6, 2025
Manifest Uses a One-Way Hash without a Salt
Moderate
CVE-2025-27408
was published
for
manifest
(npm)
Mar 3, 2025
Stage.js DOM Clobbering vulnerabilty
Moderate
CVE-2024-53386
was published
for
stage-js
(npm)
Mar 3, 2025
PrismJS DOM Clobbering vulnerability
Moderate
CVE-2024-53382
was published
for
prismjs
(npm)
Mar 3, 2025
MongoDB Shell may be susceptible to control character injection via pasting
Moderate
CVE-2025-1692
was published
for
mongosh
(npm)
Feb 27, 2025
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
Moderate
CVE-2025-27143
was published
for
better-auth
(npm)
Feb 24, 2025
Cross-site scripting (XSS) in the CKEditor 5 real-time collaboration package
Moderate
CVE-2025-25299
was published
for
@ckeditor/ckeditor5-real-time-collaboration
(npm)
Feb 20, 2025
Directus allows updates to non-allowed fields due to overlapping policies
Moderate
CVE-2025-27089
was published
for
@directus/api
(npm)
Feb 19, 2025
@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25290
was published
for
@octokit/request
(npm)
Feb 14, 2025
@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25289
was published
for
@octokit/request-error
(npm)
Feb 14, 2025
@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25288
was published
for
@octokit/plugin-paginate-rest
(npm)
Feb 14, 2025
@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
CVE-2025-25285
was published
for
@octokit/endpoint
(npm)
Feb 14, 2025
Vega allows Cross-site Scripting via the vlSelectionTuples function
Moderate
CVE-2025-25304
was published
for
vega
(npm)
Feb 14, 2025
DOMPurify allows Cross-site Scripting (XSS)
Moderate
CVE-2025-26791
was published
for
dompurify
(npm)
Feb 14, 2025
Cross-site Scripting (XSS) in serialize-javascript
Moderate
CVE-2024-11831
was published
for
serialize-javascript
(npm)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API