GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,067
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
473 advisories
Filter by severity
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
alloy-dyn-abi has DoS vulnerability on `alloy_dyn_abi::TypedData` hashing
High
CVE-2025-62370
was published
for
alloy-dyn-abi
(Rust)
Oct 15, 2025
JDBC Driver for SQL Server has improper input validation issue
High
CVE-2025-59250
was published
for
com.microsoft.sqlserver:mssql-jdbc
(Maven)
Oct 14, 2025
cel-rust May Panic During Parsing of Invalid CEL Expressions
High
CVE-2025-62162
was published
for
cel
(Rust)
Oct 11, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
Duplicate Advisory: motionEye vulnerable to RCE via unsanitized motion config parameter
High
GHSA-26f6-wm47-7h7j
was published
for
motioneye
(pip)
Oct 3, 2025
•
withdrawn
argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload
High
CVE-2025-59537
was published
for
github.com/argoproj/argo-cd
(Go)
Sep 30, 2025
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
CVE-2025-59532
was published
for
@openai/codex
(npm)
Sep 19, 2025
Apache DolphinScheduler vulnerable to Alert Script Attack
High
CVE-2024-43115
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 9, 2025
Magento vulnerable to denial of service
High
CVE-2025-49554
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
High
CVE-2025-54385
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jul 25, 2025
FastAPI Guard has a regex bypass
High
CVE-2025-54365
was published
for
fastapi-guard
(pip)
Jul 23, 2025
Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service
High
CVE-2025-47281
was published
for
github.com/kyverno/kyverno
(Go)
Jul 22, 2025
HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service
High
CVE-2025-54134
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
High
CVE-2025-50151
was published
for
org.apache.jena:jena
(Maven)
Jul 21, 2025
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
CVE-2025-22235
was published
for
org.springframework.boot:spring-boot
(Maven)
Apr 28, 2025
Shopware allows Denial Of Service via password length
High
CVE-2025-30151
was published
for
shopware/core
(Composer)
Apr 8, 2025
Synapse vulnerable to federation denial of service via malformed events
High
CVE-2025-30355
was published
for
matrix-synapse
(pip)
Mar 27, 2025
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
High
CVE-2025-1097
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized mirror annotations
High
CVE-2025-1098
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
High
CVE-2025-24514
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
Kedro allows Remote Code Execution by Pulling Micro Packages
High
CVE-2024-12215
was published
for
kedro
(pip)
Mar 20, 2025
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API