GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            3,478 advisories
        Filter by severity
        
      
      
    
                    
                      Clojure classes can be used to craft a serialized object that runs arbitrary code on deserialization
                    
                      
  Critical
                    
                
                      
                        CVE-2017-20189
                      
                      was published
                        for
                        
                          org.clojure:clojure
                        
                        (Maven)
                      Jan 22, 2024 
                    
                  
                    
                      Apache ActiveMQ is vulnerable to Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2023-46604
                      
                      was published
                        for
                        
                          org.apache.activemq:activemq-client
                        
                        (Maven)
                      Oct 27, 2023 
                    
                  
                    
                      ingress-nginx admission controller RCE escalation
                    
                      
  Critical
                    
                
                      
                        CVE-2025-1974
                      
                      was published
                        for
                        
                          k8s.io/ingress-nginx
                        
                        (Go)
                      Mar 25, 2025 
                    
                  
                    
                      Gin mishandles a wildcard at the end of an origin string
                    
                      
  Critical
                    
                
                      
                        CVE-2019-25211
                      
                      was published
                        for
                        
                          github.com/gin-contrib/cors
                        
                        (Go)
                      Jun 29, 2024 
                    
                  
                    
                      Improper Restriction of XML External Entity Reference in Liquibase
                    
                      
  Critical
                    
                
                      
                        CVE-2022-0839
                      
                      was published
                        for
                        
                          org.liquibase:liquibase-core
                        
                        (Maven)
                      Mar 5, 2022 
                    
                  
                    
                      Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
                    
                      
  Critical
                    
                
                      
                        CVE-2020-13756
                      
                      was published
                        for
                        
                          sabberworm/php-css-parser
                        
                        (Composer)
                      Mar 26, 2022 
                    
                  
                    
                      sha.js is missing type checks leading to hash rewind and passing on crafted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-9288
                      
                      was published
                        for
                        
                          sha.js
                        
                        (npm)
                      Aug 21, 2025 
                    
                  
                    
                      internetarchive Vulnerable to Directory Traversal in File.download()
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58438
                      
                      was published
                        for
                        
                          internetarchive
                        
                        (pip)
                      Sep 5, 2025 
                    
                  
                    
                      cipher-base is missing type checks, leading to hash rewind and passing on crafted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-9287
                      
                      was published
                        for
                        
                          cipher-base
                        
                        (npm)
                      Aug 21, 2025 
                    
                  
                    
                      Ruby SAML allows a SAML authentication bypass due to namespace handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25292
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      form-data uses unsafe random function in form-data for choosing boundary
                    
                      
  Critical
                    
                
                      
                        CVE-2025-7783
                      
                      was published
                        for
                        
                          form-data
                        
                        (npm)
                      Jul 21, 2025 
                    
                  
                    
                      Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-25291
                      
                      was published
                        for
                        
                          ruby-saml
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      graphql allows remote code execution when loading a crafted GraphQL schema
                    
                      
  Critical
                    
                
                      
                        CVE-2025-27407
                      
                      was published
                        for
                        
                          graphql
                        
                        (RubyGems)
                      Mar 12, 2025 
                    
                  
                    
                      Apache Tomcat - Authentication Bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2024-52316
                      
                      was published
                        for
                        
                          org.apache.tomcat:tomcat-catalina
                        
                        (Maven)
                      Nov 18, 2024 
                    
                  
                    
                      DOMPurify vulnerable to tampering by prototype polution
                    
                      
  Critical
                    
                
                      
                        CVE-2024-48910
                      
                      was published
                        for
                        
                          dompurify
                        
                        (npm)
                      Oct 31, 2024 
                    
                  
                    
                      Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54988
                      
                      was published
                        for
                        
                          org.apache.tika:tika-parser-pdf-module
                        
                        (Maven)
                      Aug 20, 2025 
                    
                  
                    
                      The ADOdb sqlite3 driver allows SQL injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54119
                      
                      was published
                        for
                        
                          adodb/adodb-php
                        
                        (Composer)
                      Aug 4, 2025 
                    
                  
                    
                      XWiki Platform allows remote code execution as guest via SolrSearchMacros request
                    
                      
  Critical
                    
                
                      
                        CVE-2025-24893
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-search-solr-ui
                        
                        (Maven)
                      Feb 20, 2025 
                    
                  
                    
                      NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54469
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
                    
                      
  Critical
                    
                
                      
                        CVE-2025-64095
                      
                      was published
                        for
                        
                          DNN.PLATFORM
                        
                        (NuGet)
                      Oct 29, 2025 
                    
                  
                    
                      OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
                    
                      
  Critical
                    
                
                      
                        CVE-2025-28384
                      
                      was published
                        for
                        
                          openc3-cosmos-tool-iframe
                        
                        (RubyGems)
                      Jun 13, 2025 
                    
                  
                    
                      m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
                    
                      
  Critical
                    
                
                      
                        GHSA-x6gv-2rvh-qmp6
                      
                      was published
                        for
                        
                          BoldestDungeon/steam-workshop-deploy
                        
                        (GitHub Actions)
                      Aug 13, 2025 
                    
                  
                    
                      Magento Community Edition Improper Input Validation vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54236
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      RoadRunner is at risk of HTTP Request/Response Smuggling through vulnerable dependency
                    
                      
  Critical
                    
                
                      
                        CVE-2025-22871
                      
                      was published
                        for
                        
                          spiral/roadrunner
                        
                        (Composer)
                      Apr 8, 2025 
                    
                  
                    
                      Karmada Dashboard API Unauthorized Access Vulnerability 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62714
                      
                      was published
                        for
                        
                          github.com/karmada-io/dashboard
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API