GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,520
Maven
5,000+
npm
4,160
NuGet
738
pip
3,959
Pub
12
RubyGems
946
Rust
1,027
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,619 advisories
Filter by severity
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Moderate
CVE-2025-59160
was published
for
matrix-js-sdk
(npm)
Sep 16, 2025
@digitalocean/do-markdownit has Type Confusion vulnerability
Moderate
CVE-2025-59717
was published
for
@digitalocean/do-markdownit
(npm)
Sep 19, 2025
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
Moderate
CVE-2025-9910
was published
for
jsondiffpatch
(npm)
Sep 11, 2025
@conventional-changelog/git-client has Argument Injection vulnerability
Moderate
CVE-2025-59433
was published
for
@conventional-changelog/git-client
(npm)
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
Moderate
CVE-2025-59535
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
Timing Attack Vulnerability in SCRAM Authentication
Moderate
CVE-2025-59432
was published
for
com.ongres.scram:scram-common
(Maven)
Sep 16, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
Moderate
GHSA-7rcc-q6rq-jpcm
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
Cloudflare Vite plugin exposes secrets over the built-in dev server
Moderate
CVE-2025-59427
was published
for
@cloudflare/vite-plugin
(npm)
Jul 8, 2025
Liferay has a stored cross-site scripting (XSS) vulnerability via a a publication’s “Name” text field
Moderate
CVE-2025-43807
was published
for
com.liferay:com.liferay.change.tracking.service
(Maven)
Sep 22, 2025
Keycloak Potential Variable Reference in Model Storage Services
Moderate
CVE-2025-9162
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Aug 21, 2025
CodeChecker has a buffer overflow in the log command
Moderate
CVE-2025-40843
was published
for
codechecker
(pip)
Sep 22, 2025
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
Moderate
CVE-2025-9862
was published
for
ghost
(npm)
Sep 15, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-43808
was published
for
com.liferay.commerce:com.liferay.commerce.product.type.virtual.service
(Maven)
Sep 19, 2025
Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-43809
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 19, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
Moderate
CVE-2025-23041
was published
for
Umbraco.Forms
(NuGet)
Jan 14, 2025
Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
Moderate
CVE-2025-53864
was published
for
com.nimbusds:nimbus-jose-jwt
(Maven)
Jul 11, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
Snipe-IT allows XSS
Moderate
CVE-2025-59712
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
Snipe-IT allows unsafe deserialization
Moderate
CVE-2025-59713
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages
Moderate
CVE-2025-59417
was published
for
@lobehub/chat
(npm)
Sep 18, 2025
ggit is vulnerable to Arbitrary Argument Injection via the clone() API
Moderate
CVE-2024-21533
was published
for
ggit
(npm)
Oct 8, 2024
DragonFly's tiny file download uses hard coded HTTP protocol
Moderate
CVE-2025-59410
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components
Moderate
CVE-2025-1647
was published
for
bootstrap
(npm)
May 15, 2025
ProTip!
Advisories are also available from the
GraphQL API