GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,035 advisories
        Filter by severity
        
      
      
    
                    
                      Remote Code Execution Vulnerability in NPM mongo-express
                    
                      
  Critical
                    
                
                      
                        CVE-2019-10758
                      
                      was published
                        for
                        
                          mongo-express
                        
                        (npm)
                      Dec 30, 2019 
                    
                  
                    
                      FlowiseAI Pre-Auth Arbitrary Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-57164
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
                    
                      Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
                    
                      
  Critical
                    
                
                      
                        GHSA-3g4j-r53p-22wx
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62410
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
                    
                      Expo SDK has an OAuth vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2023-28131
                      
                      was published
                        for
                        
                          expo
                        
                        (npm)
                      Apr 24, 2023 
                    
                  
                    
                      @nx/azure-cache Vulnerable to Build Cache Poisoning via Untrusted Pull Requests
                    
                      
  Critical
                    
                
                      
                        CVE-2025-36852
                      
                      was published
                        for
                        
                          @nx/azure-cache
                        
                        (npm)
                      Jun 10, 2025 
                    
                  
                    
                      Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
                    
                      
  Critical
                    
                
                      
                        CVE-2025-50538
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 3, 2025 
                    
                  
                    
                      Happy DOM: VM Context Escape can lead to Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61927
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 10, 2025 
                    
                  
                    
                      Better Auth: Unauthenticated API key creation through api-key plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61928
                      
                      was published
                        for
                        
                          better-auth
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
                    
                      Authorization Bypass in Next.js Middleware
                    
                      
  Critical
                    
                
                      
                        CVE-2025-29927
                      
                      was published
                        for
                        
                          next
                        
                        (npm)
                      Mar 21, 2025 
                    
                  
                    
                      Flowise is vulnerable to arbitrary file write through its WriteFileTool 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61913
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
                    
                      SillyTavern Web Interface Vulnerable DNS Rebinding
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59159
                      
                      was published
                        for
                        
                          sillytavern
                        
                        (npm)
                      Oct 6, 2025 
                    
                  
                    
                      Flowise vulnerable to RCE via Dynamic function constructor injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55346
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 6, 2025 
                    
                  
                    
                      Duplicate Advisory: Flowise vulnerable to RCE via Dynamic function constructor injection
                    
                      
  Critical
                    
                
                      
                        GHSA-q4xx-mc3q-23x8
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Aug 14, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      check-branches is vulnerable to command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-11148
                      
                      was published
                        for
                        
                          check-branches
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      DocsGPT Allows Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-0868
                      
                      was published
                        for
                        
                          docsgpt
                        
                        (npm)
                      Feb 20, 2025 
                    
                  
                    
                      get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59936
                      
                      was published
                        for
                        
                          get-jwks
                        
                        (npm)
                      Sep 26, 2025 
                    
                  
                    
                      cors-anywhere vulnerable to server-side request forgery
                    
                      
  Critical
                    
                
                      
                        CVE-2020-36851
                      
                      was published
                        for
                        
                          cors-anywhere
                        
                        (npm)
                      Sep 25, 2025 
                    
                  
                    
                      Command Injection in adb-mcp MCP Server
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59834
                      
                      was published
                        for
                        
                          adb-mcp
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      Malicious versions of Nx were published
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10894
                      
                      was published
                        for
                        
                          @nx/devkit
                        
                        (npm)
                      Aug 27, 2025 
                    
                  
                    
                      Duplicate Advisory: Malicious versions of Nx were published
                    
                      
  Critical
                    
                
                      
                        GHSA-8mjq-32x3-22qf
                      
                      was published
                        for
                        
                          nx
                        
                        (npm)
                      Sep 25, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      CleverTap Cordova plugin vulnerable to Cross-site Scripting
                    
                      
  Critical
                    
                
                      
                        CVE-2023-2507
                      
                      was published
                        for
                        
                          clevertap-cordova
                        
                        (npm)
                      Jul 15, 2023 
                    
                  
                    
                      CodeceptJS's incomprehensive sanitation can lead to Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-57285
                      
                      was published
                        for
                        
                          codeceptjs
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      Flowise has Remote Code Execution vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59528
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
                    
                      Flowise has arbitrary file access due to missing chat flow id validation
                    
                      
  Critical
                    
                
                      
                        GHSA-q67q-549q-p849
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API