GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,486
Maven
5,000+
npm
4,104
NuGet
735
pip
3,918
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,104 advisories
Filter by severity
@backstage/backend-app-api leaks GitLab access tokens
High
CVE-2023-6944
was published
for
@backstage/backend-app-api
(npm)
Jan 4, 2024
Hono's flaw in URL path parsing could cause path confusion
High
CVE-2025-58362
was published
for
hono
(npm)
Sep 3, 2025
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
High
CVE-2025-58179
was published
for
@astrojs/cloudflare
(npm)
Sep 4, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
Hexo `include_code` has a path traversal
High
CVE-2023-39584
was published
for
hexo
(npm)
Sep 8, 2023
Directus incorrectly handles `_in` filter
High
CVE-2024-39701
was published
for
directus
(npm)
Jul 8, 2024
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool
High
CVE-2025-58358
was published
for
mcp-markdownify-server
(npm)
Sep 2, 2025
CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package
Low
CVE-2025-58064
was published
for
@ckeditor/ckeditor5-clipboard
(npm)
Sep 3, 2025
Mermaid improperly sanitizes sequence diagram labels leading to XSS
Moderate
CVE-2025-54881
was published
for
mermaid
(npm)
Aug 19, 2025
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
High
GHSA-ph6w-f82w-28w6
was published
for
@anthropic-ai/claude-code
(npm)
Sep 3, 2025
utils-extend Prototype Pollution
Critical
CVE-2024-57077
was published
for
utils-extend
(npm)
Feb 6, 2025
nodemailer ReDoS when trying to send a specially crafted email
Moderate
GHSA-9h6g-pr28-7cqp
was published
for
nodemailer
(npm)
Jan 31, 2024
useragent Regular Expression Denial of Service vulnerability
Moderate
CVE-2020-26311
was published
for
useragent
(npm)
Oct 26, 2024
domain-suffix RegEx Denial of Service
High
CVE-2024-25354
was published
for
domain-suffix
(npm)
Mar 28, 2024
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Moderate
CVE-2025-57752
was published
for
next
(npm)
Aug 29, 2025
parse-uri Regular expression Denial of Service (ReDoS)
Moderate
CVE-2024-36751
was published
for
parse-uri
(npm)
Jan 16, 2025
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
org.webjars:swagger-ui
(Maven)
Mar 12, 2022
Malicious versions of Nx were published
Critical
GHSA-cxm3-wv7p-598c
was published
for
@nx/devkit
(npm)
Aug 27, 2025
Next.js Improper Middleware Redirect Handling Leads to SSRF
Moderate
CVE-2025-57822
was published
for
next
(npm)
Aug 29, 2025
Next.js Content Injection Vulnerability for Image Optimization
Moderate
CVE-2025-55173
was published
for
next
(npm)
Aug 29, 2025
AiondaDotCom mcp-ssh command injection vulnerability in SSH operations
Moderate
CVE-2025-9654
was published
for
@aiondadotcom/mcp-ssh
(npm)
Aug 29, 2025
Payload's SQLite adapter Session Fixation vulnerability
Moderate
CVE-2025-4644
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
Payload does not invalidate JWTs after log out
Moderate
CVE-2025-4643
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
Volto affected by possible DoS by invoking specific URL by anonymous user
High
CVE-2025-58047
was published
for
@plone/volto
(npm)
Aug 28, 2025
ProTip!
Advisories are also available from the
GraphQL API