GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,615 advisories
Filter by severity
Rancher exposes sensitive information through audit logs
Moderate
CVE-2024-58269
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
sqls-server/sqls is vulnerable to command injection in the config command
High
CVE-2025-61141
was published
for
github.com/sqls-server/sqls
(Go)
Oct 30, 2025
NeuVector is shipping cryptographic material into its binary
Moderate
CVE-2025-54471
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
NeuVector telemetry sender is vulnerable to MITM and DoS
High
CVE-2025-54470
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
gnark-crypto allows unchecked memory allocation during vector deserialization
High
GHSA-fj2x-735w-74vq
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 30, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Low
GHSA-cf57-c578-7jvv
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
Critical
CVE-2025-54469
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Zitadel May Bypass Second Authentication Factor
High
CVE-2025-64103
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
Zitadel allows brute-forcing authentication factors
High
CVE-2025-64102
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
Rancher user retains access to clusters despite Global Role removal
Moderate
CVE-2023-32199
was published
for
github.com/rancher/rancher
(Go)
Oct 24, 2025
Consul event endpoint is vulnerable to denial of service
Moderate
CVE-2025-11375
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Consul key/value endpoint is vulnerable to denial of service
Moderate
CVE-2025-11374
was published
for
github.com/hashicorp/consul
(Go)
Oct 28, 2025
Silver has unrestricted traffic between Wireguard clients
Moderate
CVE-2025-27093
was published
for
github.com/bishopfox/sliver
(Go)
Oct 28, 2025
otelgrpc DoS vulnerability due to unbound cardinality metrics
High
CVE-2023-47108
was published
for
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc
(Go)
Nov 12, 2023
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
High
CVE-2025-62506
was published
for
github.com/minio/minio
(Go)
Oct 16, 2025
Mattermost Server's OAuth 2.0 service is vulnerable to attack through Missing Authorization
Moderate
CVE-2017-18872
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Karmada Dashboard API Unauthorized Access Vulnerability
Critical
CVE-2025-62714
was published
for
github.com/karmada-io/dashboard
(Go)
Oct 24, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
High
CVE-2025-11621
was published
for
github.com/hashicorp/vault
(Go)
Oct 23, 2025
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
High
CVE-2025-12044
was published
for
github.com/hashicorp/vault
(Go)
Oct 23, 2025
ProTip!
Advisories are also available from the
GraphQL API