GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,890
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,215
NuGet
744
pip
3,991
Pub
12
RubyGems
950
Rust
1,038
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,030 advisories
Filter by severity
Better Auth: Unauthenticated API key creation through api-key plugin
Critical
GHSA-99h5-pjcv-gr6v
was published
for
better-auth
(npm)
Oct 9, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
flowise
(npm)
Oct 9, 2025
SillyTavern Web Interface Vulnerable DNS Rebinding
Critical
CVE-2025-59159
was published
for
sillytavern
(npm)
Oct 6, 2025
Flowise vulnerable to RCE via Dynamic function constructor injection
Critical
CVE-2025-55346
was published
for
flowise
(npm)
Oct 6, 2025
Duplicate Advisory: Flowise vulnerable to RCE via Dynamic function constructor injection
Critical
GHSA-q4xx-mc3q-23x8
was published
for
flowise
(npm)
Aug 14, 2025
•
withdrawn
Flowise vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
GHSA-964p-j4gg-mhwc
was published
for
flowise
(npm)
Oct 3, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
DocsGPT Allows Remote Code Execution
Critical
CVE-2025-0868
was published
for
docsgpt
(npm)
Feb 20, 2025
get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass
Critical
CVE-2025-59936
was published
for
get-jwks
(npm)
Sep 26, 2025
cors-anywhere vulnerable to server-side request forgery
Critical
CVE-2020-36851
was published
for
cors-anywhere
(npm)
Sep 25, 2025
Command Injection in adb-mcp MCP Server
Critical
CVE-2025-59834
was published
for
adb-mcp
(npm)
Sep 24, 2025
Malicious versions of Nx were published
Critical
CVE-2025-10894
was published
for
@nx/devkit
(npm)
Aug 27, 2025
Duplicate Advisory: Malicious versions of Nx were published
Critical
GHSA-8mjq-32x3-22qf
was published
for
nx
(npm)
Sep 25, 2025
•
withdrawn
CleverTap Cordova plugin vulnerable to Cross-site Scripting
Critical
CVE-2023-2507
was published
for
clevertap-cordova
(npm)
Jul 15, 2023
CodeceptJS's incomprehensive sanitation can lead to Command Injection
Critical
CVE-2025-57285
was published
for
codeceptjs
(npm)
Sep 8, 2025
Flowise has Remote Code Execution vulnerability
Critical
CVE-2025-59528
was published
for
flowise
(npm)
Sep 15, 2025
Flowise has arbitrary file access due to missing chat flow id validation
Critical
GHSA-q67q-549q-p849
was published
for
flowise
(npm)
Sep 15, 2025
Flowise has an Arbitrary File Read
Critical
GHSA-99pg-hqvx-r4gf
was published
for
flowise
(npm)
Sep 15, 2025
FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
GHSA-7944-7c6r-55vv
was published
for
flowise
(npm)
Sep 15, 2025
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Critical
CVE-2025-58434
was published
for
flowise
(npm)
Sep 12, 2025
sha.js is missing type checks leading to hash rewind and passing on crafted data
Critical
CVE-2025-9288
was published
for
sha.js
(npm)
Aug 21, 2025
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
Critical
CVE-2025-9287
was published
for
cipher-base
(npm)
Aug 21, 2025
Prebid-universal-creative latest on npm briefly compromised
Critical
CVE-2025-59039
was published
for
prebid-universal-creative
(npm)
Sep 11, 2025
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
Authorization Bypass in Next.js Middleware
Critical
CVE-2025-29927
was published
for
next
(npm)
Mar 21, 2025
ProTip!
Advisories are also available from the
GraphQL API