GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,658
Maven
5,000+
npm
4,288
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,751 advisories
Filter by severity
Astro Development Server has Arbitrary Local File Read
Low
CVE-2025-64757
was published
for
astro
(npm)
Nov 19, 2025
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and...
Low
Unreviewed
CVE-2025-11990
was published
Nov 15, 2025
A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME...
Low
Unreviewed
CVE-2025-4945
was published
May 19, 2025
Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels
Low
CVE-2025-13083
was published
for
drupal/core
(Composer)
Nov 18, 2025
LibreNMS has Weak Password Policy
Low
CVE-2025-65014
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Drupal Simple multi step form allows Cross-Site Scripting
Low
CVE-2025-12761
was published
for
drupal/simple_multistep
(Composer)
Nov 18, 2025
Drupal core allows Content Spoofing
Low
CVE-2025-13082
was published
for
drupal/core
(Composer)
Nov 18, 2025
Drupal core allows Forceful Browsing
Low
CVE-2025-13080
was published
for
drupal/core
(Composer)
Nov 18, 2025
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could...
Low
Unreviewed
CVE-2025-52639
was published
Nov 18, 2025
Mattermost allows other users to determine when users had read channels via channel member objects
Low
CVE-2025-55074
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 18, 2025
Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution...
Low
Unreviewed
CVE-2025-63292
was published
Nov 17, 2025
An Improper Privilege Management vulnerability [CWE-269] in Fortinet FortiOS 7.6.0 through 7.6.3,...
Low
Unreviewed
CVE-2025-54821
was published
Nov 18, 2025
Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an...
Low
Unreviewed
CVE-2025-64734
was published
Nov 18, 2025
The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without...
Low
Unreviewed
CVE-2025-12792
was published
Nov 18, 2025
GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy...
Low
Unreviewed
CVE-2025-65083
was published
Nov 17, 2025
A relative path traversal vulnerability has been reported to affect Download Station. If a remote...
Low
Unreviewed
CVE-2025-58463
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a...
Low
Unreviewed
CVE-2025-58465
was published
Nov 7, 2025
Mattermost allows regular users to access archived channel content and files
Low
CVE-2025-41436
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10...
Low
Unreviewed
CVE-2025-60022
was published
Nov 17, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18...
Low
Unreviewed
CVE-2025-7736
was published
Nov 15, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18...
Low
Unreviewed
CVE-2025-12983
was published
Nov 15, 2025
GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4...
Low
Unreviewed
CVE-2025-6945
was published
Nov 15, 2025
Astro development server error page vulnerable to reflected Cross-site Scripting
Low
CVE-2025-64745
was published
for
astro
(npm)
Nov 13, 2025
sudo-rs: Partial password reveal is possible after timeout
Low
CVE-2025-64170
was published
for
sudo-rs
(Rust)
Nov 12, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-53412
was published
Nov 7, 2025
ProTip!
Advisories are also available from the
GraphQL API