GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,134 advisories
Filter by severity
secrets-store-sync-controller discloses service account tokens in logs
Moderate
CVE-2025-7445
was published
for
sigs.k8s.io/secrets-store-sync-controller
(Go)
Sep 5, 2025
Memos Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2025-56761
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
Memos Vulnerable to Path Traversal via the CreateResource Endpoint
Moderate
CVE-2025-56760
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
github.com/gorilla/csrf improperly validates TrustedOrigins allowing CSRF attacks
Moderate
CVE-2025-47909
was published
for
github.com/gorilla/csrf
(Go)
Aug 29, 2025
github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
Moderate
CVE-2025-58058
was published
for
github.com/ulikunitz/xz
(Go)
Aug 28, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector has an insecure password storage vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
traQ Allows Insertion of Sensitive Information into Log File
Moderate
CVE-2025-57813
was published
for
github.com/traPtitech/traQ
(Go)
Aug 26, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data
Moderate
CVE-2025-8402
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data
Moderate
GHSA-2464-8j7c-4cjm
was published
for
github.com/go-viper/mapstructure/v2
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions
Moderate
CVE-2025-49222
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
CRI-O has Potential High Memory Consumption from File Read
Moderate
CVE-2025-4437
was published
for
github.com/cri-o/cri-o
(Go)
Aug 20, 2025
Default Credentials in nginx-defender Configuration Files
Moderate
CVE-2025-55740
was published
for
github.com/Anipaleja/nginx-defender
(Go)
Aug 19, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-55213
was published
for
github.com/openfga/openfga
(Go)
Aug 18, 2025
Information Disclosure in Amazon ECS Container Agent
Moderate
CVE-2025-9039
was published
for
github.com/aws/amazon-ecs-agent
(Go)
Aug 14, 2025
Helm May Panic Due To Incorrect YAML Content
Moderate
CVE-2025-55198
was published
for
helm.sh/helm/v3
(Go)
Aug 14, 2025
Helm Charts with Specific JSON Schema Values Can Cause Memory Exhaustion
Moderate
CVE-2025-55199
was published
for
helm.sh/helm/v3
(Go)
Aug 14, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Moderate
CVE-2025-53514
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-53910
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
ProTip!
Advisories are also available from the
GraphQL API