GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,688
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,636 advisories
Filter by severity
gokey allows secret recovery from a seed file without the master password
High
CVE-2025-13353
was published
for
github.com/cloudflare/gokey
(Go)
Dec 2, 2025
vLLM vulnerable to remote code execution via transformers_utils/get_config
High
CVE-2025-66448
was published
for
vllm
(pip)
Dec 2, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
High
CVE-2025-66298
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
High
CVE-2025-66294
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
High
CVE-2025-66297
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
High
CVE-2025-66295
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes
High
CVE-2025-66412
was published
for
@angular/compiler
(npm)
Dec 2, 2025
Gin-vue-admin has an arbitrary file deletion vulnerability
High
CVE-2025-66410
was published
for
github.com/flipped-aurora/gin-vue-admin
(Go)
Dec 2, 2025
Keras Directory Traversal Vulnerability
High
CVE-2025-12060
was published
for
keras
(pip)
Dec 2, 2025
Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter
High
CVE-2025-66305
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
High
CVE-2025-66301
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to Arbitrary File Read
High
CVE-2025-66300
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)
High
CVE-2025-66299
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
High
CVE-2025-66296
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
XWiki Jetty Package (XJetty) allows accessing any application file through URL
High
CVE-2025-55749
was published
for
org.xwiki.platform:xwiki-platform-tool-jetty-resources
(Maven)
Dec 1, 2025
trytond does not enforce access rights for the route of the HTML editor.
High
CVE-2025-66423
was published
for
trytond
(pip)
Nov 30, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12638
was published
for
Keras
(pip)
Nov 28, 2025
•
withdrawn
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements
High
CVE-2025-12758
was published
for
validator
(npm)
Nov 27, 2025
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client
High
CVE-2025-66035
was published
for
@angular/common
(npm)
Nov 26, 2025
node-forge has ASN.1 Unbounded Recursion
High
CVE-2025-66031
was published
for
node-forge
(npm)
Nov 26, 2025
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
High
CVE-2025-12816
was published
for
node-forge
(npm)
Nov 26, 2025
Valibot has a ReDoS vulnerability in `EMOJI_REGEX`
High
CVE-2025-66020
was published
for
valibot
(npm)
Nov 26, 2025
OneUptime Unauthorized User Creation via API
High
CVE-2025-65966
was published
for
@oneuptime/common
(npm)
Nov 26, 2025
ProTip!
Advisories are also available from the
GraphQL API