GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,034
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,127 advisories
        Filter by severity
        
      
      
    
                    
                      NextAuthjs Email misdelivery Vulnerability
                    
                      
  Moderate
                    
                
                      
                        GHSA-5jpx-9hw9-2fx4
                      
                      was published
                        for
                        
                          next-auth
                        
                        (npm)
                      Oct 29, 2025 
                    
                  
                    
                      BBOT's gitlab.py exposes globally configured "gitlab" API key
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10282
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 27, 2025 
                    
                  
                    
                      Moodle exposed the names of hidden groups to users
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62400
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Oct 23, 2025 
                    
                  
                    
                      Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53092
                      
                      was published
                        for
                        
                          @strapi/core
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Omni vulnerable to information leak via API
                    
                      
  High
                    
                
                      
                        CVE-2025-61688
                      
                      was published
                        for
                        
                          github.com/siderolabs/omni
                        
                        (Go)
                      Oct 13, 2025 
                    
                  
                    
                      Rack has a Possible Information Disclosure Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61780
                      
                      was published
                        for
                        
                          rack
                        
                        (RubyGems)
                      Oct 10, 2025 
                    
                  
                    
                      BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10281
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      Canonical LXD Project Existence Determination Through Error Handling in Image Export Function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54290
                      
                      was published
                        for
                        
                          github.com/canonical/lxd
                        
                        (Go)
                      Oct 2, 2025 
                    
                  
                    
                      FormCMS has an improper access control vulnerability in the /api/schemas/history/[schemaId] endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55797
                      
                      was published
                        for
                        
                          FormCMS
                        
                        (NuGet)
                      Sep 30, 2025 
                    
                  
                    
                      OpenMLS improper persistence of the secret tree during message processing
                    
                      
  Moderate
                    
                
                      
                        GHSA-qr9h-x63w-vqfm
                      
                      was published
                        for
                        
                          openmls
                        
                        (Rust)
                      Sep 26, 2025 
                    
                  
                    
                      Rancher sends sensitive information to external services through the `/meta/proxy` endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54468
                      
                      was published
                        for
                        
                          github.com/rancher/rancher
                        
                        (Go)
                      Sep 26, 2025 
                    
                  
                    
                      ml-logger file handler allows reading arbitrary files
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10952
                      
                      was published
                        for
                        
                          ml-logger
                        
                        (pip)
                      Sep 25, 2025 
                    
                  
                    
                      WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
                    
                      
  High
                    
                
                      
                        CVE-2025-54376
                      
                      was published
                        for
                        
                          github.com/SpectoLabs/hoverfly
                        
                        (Go)
                      Sep 10, 2025 
                    
                  
                    
                      Vite middleware may serve files starting with the same name with the public directory
                    
                      
  Low
                    
                
                      
                        CVE-2025-58751
                      
                      was published
                        for
                        
                          vite
                        
                        (npm)
                      Sep 9, 2025 
                    
                  
                    
                      Vite's `server.fs` settings were not applied to HTML files
                    
                      
  Low
                    
                
                      
                        CVE-2025-58752
                      
                      was published
                        for
                        
                          vite
                        
                        (npm)
                      Sep 9, 2025 
                    
                  
                    
                      TYPO3 Workspaces Module Information Disclosure
                    
                      
  High
                    
                
                      
                        CVE-2025-59018
                      
                      was published
                        for
                        
                          typo3/cms-workspaces
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      TYPO3 CSV download feature information disclosure
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59019
                      
                      was published
                        for
                        
                          typo3/cms-backend
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      Atlantis Exposes Service Version Publicly on /status API Endpoint
                    
                      
  Low
                    
                
                      
                        CVE-2025-58445
                      
                      was published
                        for
                        
                          github.com/runatlantis/atlantis
                        
                        (Go)
                      Sep 5, 2025 
                    
                  
                    
                      Argo CD's Project API Token Exposes Repository Credentials
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55190
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd/v2
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Langchain Community Vulnerable to XML External Entity (XXE) Attacks
                    
                      
  High
                    
                
                      
                        CVE-2025-6984
                      
                      was published
                        for
                        
                          langchain-community
                        
                        (pip)
                      Sep 4, 2025 
                    
                  
                    
                      Jenkins Git client Plugin file system information disclosure vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-58458
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:git-client
                        
                        (Maven)
                      Sep 3, 2025 
                    
                  
                    
                      Valtimo scripting engine can be used to gain access to sensitive data or resources
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58059
                      
                      was published
                        for
                        
                          com.ritense.valtimo:core
                        
                        (Maven)
                      Aug 28, 2025 
                    
                  
                    
                      Contao can disclose sensitive information in the news module
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57757
                      
                      was published
                        for
                        
                          contao/contao
                        
                        (Composer)
                      Aug 28, 2025 
                    
                  
                    
                      Contao discloses sensitive information in the front end search index
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57756
                      
                      was published
                        for
                        
                          contao/contao
                        
                        (Composer)
                      Aug 28, 2025 
                    
                  
                    
                      @musistudio/claude-code-router has improper CORS configuration
                    
                      
  High
                    
                
                      
                        CVE-2025-57755
                      
                      was published
                        for
                        
                          @musistudio/claude-code-router
                        
                        (npm)
                      Aug 21, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API