GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,067
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
448 advisories
Filter by severity
Directus is Vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-64747
was published
for
directus
(npm)
Nov 14, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
Astro's `X-Forwarded-Host` is reflected without validation
Moderate
CVE-2025-61925
was published
for
astro
(npm)
Oct 10, 2025
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
Moderate
CVE-2025-61620
was published
for
vllm
(pip)
Oct 7, 2025
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
Moderate
CVE-2025-13033
was published
for
nodemailer
(npm)
Oct 7, 2025
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing
Moderate
CVE-2025-11226
was published
for
ch.qos.logback:logback-core
(Maven)
Oct 1, 2025
mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders
Moderate
CVE-2025-59940
was published
for
mkdocs-include-markdown-plugin
(pip)
Sep 29, 2025
Llama Stack could potentially allow for remote code execution
Moderate
CVE-2025-55178
was published
for
llama-stack
(pip)
Sep 24, 2025
Apache IoTDB: DoS Vulnerability
Moderate
CVE-2025-48392
was published
for
org.apache.iotdb:iotdb-core
(Maven)
Sep 24, 2025
DNN allows loading unused themes on anonymous clients through query parameters
Moderate
CVE-2025-59535
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Moderate
CVE-2025-59160
was published
for
matrix-js-sdk
(npm)
Sep 16, 2025
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Moderate
CVE-2025-10164
was published
for
sglang
(pip)
Sep 9, 2025
TinyEnv: Inline comments not stripped properly in .env values
Moderate
CVE-2025-58759
was published
for
datahihi1/tiny-env
(Composer)
Sep 9, 2025
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
Vaadin Platform possible file bypass via upload validation on the server-side
Moderate
GHSA-c7v7-rqfm-f44j
was published
for
com.vaadin:vaadin
(Maven)
Sep 4, 2025
Vaadin Flow Components possible file bypass via upload validation on the server-side
Moderate
GHSA-94g8-xv23-7656
was published
for
com.vaadin:vaadin-upload-flow
(Maven)
Sep 4, 2025
Vaadin Framework possible file bypass via upload validation on the server-side
Moderate
CVE-2025-9467
was published
for
com.vaadin:vaadin-server
(Maven)
Sep 4, 2025
Next.js Content Injection Vulnerability for Image Optimization
Moderate
CVE-2025-55173
was published
for
next
(npm)
Aug 29, 2025
Apache CXF: Untrusted JMS configuration can lead to RCE
Moderate
CVE-2025-48913
was published
for
org.apache.cxf:cxf-rt-transports-jms
(Maven)
Aug 8, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-54368
was published
for
uv
(pip)
Aug 7, 2025
Ollama allows deletion of arbitrary files
Moderate
CVE-2025-44779
was published
for
github.com/ollama/ollama
(Go)
Aug 7, 2025
Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
Moderate
CVE-2025-8571
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
Moderate
CVE-2024-52279
was published
for
org.apache.zeppelin:zeppelin-jdbc
(Maven)
Aug 3, 2025
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
ProTip!
Advisories are also available from the
GraphQL API