GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,255 advisories
Filter by severity
TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update
High
CVE-2025-60542
was published
for
typeorm
(npm)
Oct 29, 2025
messageformat prototype pollution vulnerability
Moderate
CVE-2025-57353
was published
for
@messageformat/runtime
(npm)
Sep 24, 2025
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
High
CVE-2025-62726
was published
for
n8n
(npm)
Oct 30, 2025
node-tar has a race condition leading to uninitialized memory exposure
Moderate
CVE-2025-64118
was published
for
tar
(npm)
Oct 30, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
NextAuthjs Email misdelivery Vulnerability
Moderate
GHSA-5jpx-9hw9-2fx4
was published
for
next-auth
(npm)
Oct 29, 2025
validator.js has a URL validation bypass vulnerability in its isURL function
Moderate
CVE-2025-56200
was published
for
validator
(npm)
Sep 30, 2025
Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate
High
CVE-2025-59288
was published
for
playwright
(npm)
Oct 14, 2025
rollbar vulnerable to Prototype Pollution in merge()
Moderate
CVE-2025-62517
was published
for
rollbar
(npm)
Oct 23, 2025
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
GHSA-q7jf-gf43-6x6p
was published
for
hono
(npm)
Oct 24, 2025
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
Hono Improper Authorization vulnerability
High
CVE-2025-62610
was published
for
hono
(npm)
Oct 22, 2025
Strapi is vulnerable to Insufficient Session Expiration
Moderate
CVE-2025-3930
was published
for
@strapi/strapi
(npm)
Oct 16, 2025
Command Injection Vulnerability
High
CVE-2021-21315
was published
for
systeminformation
(npm)
Feb 16, 2021
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11023
was published
for
components/jquery
(RubyGems)
Apr 29, 2020
Remote Code Execution Vulnerability in NPM mongo-express
Critical
CVE-2019-10758
was published
for
mongo-express
(npm)
Dec 30, 2019
Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
Moderate
CVE-2025-62595
was published
for
koa
(npm)
Oct 21, 2025
vite allows server.fs.deny bypass via backslash on Windows
Moderate
CVE-2025-62522
was published
for
vite
(npm)
Oct 20, 2025
rollbar vulnerable to prototype pollution
Low
CVE-2025-57325
was published
for
rollbar
(npm)
Oct 20, 2025
Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
Moderate
GHSA-vffh-c9pq-4crh
was published
for
uptime-kuma
(npm)
Oct 20, 2025
Cross-site Scripting (XSS) in @scullyio/scully
High
CVE-2020-28470
was published
for
@scullyio/ng-lib
(npm)
Apr 13, 2021
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
Moderate
GHSA-xvp7-8vm8-xfxx
was published
for
@actual-app/sync-server
(npm)
Oct 20, 2025
Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
Low
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
•
withdrawn
Duplicate Advisory: rollbar vulnerable to prototype pollution
Low
GHSA-m929-rg27-gj99
was published
for
rollbar
(npm)
Sep 24, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API