GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,506 advisories
Filter by severity
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Critical
CVE-2025-62593
was published
for
ray
(pip)
Nov 26, 2025
Apache Druid’s Kerberos authenticator uses a weak fallback secret
Critical
CVE-2025-59390
was published
for
org.apache.druid:druid
(Maven)
Nov 26, 2025
libnftnl has Heap-based Buffer Overflow in nftnl::Batch::with_page_size (nftnl-rs)
Critical
GHSA-2fjw-whxm-9v4q
was published
for
nftnl
(Rust)
Nov 25, 2025
cggmp21 has a missing check in the ZK proof used in CGGMP21
Critical
CVE-2025-66016
was published
for
cggmp21
(Rust)
Nov 25, 2025
LF Edge eKuiper is vulnerable to Arbitrary File Read/Write via unsanitized names and zip extraction
Critical
GHSA-rj4j-2jph-gg43
was published
for
github.com/lf-edge/ekuiper/v2
(Go)
Nov 24, 2025
Grafana Incorrect Privilege Assignment vulnerability
Critical
CVE-2025-41115
was published
for
github.com/grafana/grafana
(Go)
Nov 21, 2025
md-to-pdf vulnerable to arbitrary JavaScript code execution when parsing front matter
Critical
CVE-2025-65108
was published
for
md-to-pdf
(npm)
Nov 20, 2025
@hpke/core reuses AEAD nonces
Critical
CVE-2025-64767
was published
for
@hpke/core
(npm)
Nov 20, 2025
Apache Causeway vulnerable to deserialization in Java
Critical
CVE-2025-64408
was published
for
org.apache.causeway.commons:causeway-commons
(Maven)
Nov 19, 2025
Modular Max Serve has Unsafe Deserialization vulnerability
Critical
CVE-2025-60455
was published
for
modular
(pip)
Nov 18, 2025
Eclipse Jersey has a Race Condition
Critical
CVE-2025-12383
was published
for
org.glassfish.jersey.core:jersey-client
(Maven)
Nov 18, 2025
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
Critical
CVE-2025-65015
was published
for
joserfc
(pip)
Nov 18, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
File Browser has risk of HTTP Request/Response smuggling through vulnerable dependency
Critical
GHSA-6jqf-mv7m-3q7p
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Nov 13, 2025
Milvus Proxy has a Critical Authentication Bypass Vulnerability
Critical
CVE-2025-64513
was published
for
github.com/milvus-io/milvus
(Go)
Nov 13, 2025
pgAdmin4 vulnerable to Remote Code Execution (RCE) when running in server mode
Critical
CVE-2025-12762
was published
for
pgadmin4
(pip)
Nov 13, 2025
Soft Serve is vulnerable to SSRF through its Webhooks
Critical
CVE-2025-64522
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 10, 2025
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Critical
CVE-2025-64459
was published
for
django
(pip)
Nov 5, 2025
@react-native-community/cli has arbitrary OS command injection
Critical
CVE-2025-11953
was published
for
@react-native-community/cli
(npm)
Nov 3, 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
Critical
CVE-2025-64095
was published
for
DNN.PLATFORM
(NuGet)
Oct 29, 2025
Karmada Dashboard API Unauthorized Access Vulnerability
Critical
CVE-2025-62714
was published
for
github.com/karmada-io/dashboard
(Go)
Oct 24, 2025
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
Critical
CVE-2025-54469
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
Cosmos EVM Vulnerability
Critical
GHSA-8pfh-j44r-f654
was published
for
github.com/cosmos/evm
(Go)
Oct 21, 2025
NetBird VPN does not remove the default password of an admin account
Critical
CVE-2025-10678
was published
for
github.com/netbirdio/netbird
(Go)
Oct 20, 2025
MCMS vulnerable SQL injection via the content_title parameter
Critical
CVE-2025-56316
was published
for
net.mingsoft:ms-mcms
(Maven)
Oct 17, 2025
ProTip!
Advisories are also available from the
GraphQL API