GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,473
Maven
5,000+
npm
4,091
NuGet
734
pip
3,907
Pub
12
RubyGems
944
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,677 advisories
Filter by severity
github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
Moderate
CVE-2025-58058
was published
for
github.com/ulikunitz/xz
(Go)
Aug 28, 2025
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token
Low
GHSA-3rw9-wmc8-8948
was published
for
github.com/coder/coder/v2
(Go)
Aug 28, 2025
Contrast leaks workload secrets to logs on INFO level
High
GHSA-vxg3-w9rv-rhr2
was published
for
github.com/edgelesssys/contrast
(Go)
Aug 28, 2025
Valtimo scripting engine can be used to gain access to sensitive data or resources
Critical
CVE-2025-58059
was published
for
com.ritense.valtimo:core
(Maven)
Aug 28, 2025
Volto affected by possible DoS by invoking specific URL by anonymous user
High
CVE-2025-58047
was published
for
@plone/volto
(npm)
Aug 28, 2025
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
XWiki PDF export jobs store sensitive cookies unencrypted in job statuses
Moderate
CVE-2025-58049
was published
for
org.xwiki.platform:xwiki-platform-export-pdf-api
(Maven)
Aug 28, 2025
Contao does not properly manage privileges for page and article fields
Moderate
CVE-2025-57759
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao can disclose sensitive information in the news module
Moderate
CVE-2025-57757
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao discloses sensitive information in the front end search index
Moderate
CVE-2025-57756
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao applies improper access control in the back end voters
Moderate
CVE-2025-57758
was published
for
contao/contao
(Composer)
Aug 28, 2025
lychee link checking action affected by arbitrary code injection in composite action
Moderate
CVE-2024-48908
was published
for
lycheeverse/lychee-action
(GitHub Actions)
Aug 28, 2025
NeuVector admin account has insecure default password
Critical
CVE-2025-8077
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector has an insecure password storage vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
simple-admin-core SQL Injection vulnerability
High
CVE-2025-51667
was published
for
github.com/suyuan32/simple-admin-core
(Go)
Aug 27, 2025
Google Sign-In for Rails allowed redirects to malformed URLs
Moderate
CVE-2025-57821
was published
for
google_sign_in
(RubyGems)
Aug 27, 2025
Malicious versions of Nx were published
Critical
GHSA-cxm3-wv7p-598c
was published
for
@nx/devkit
(npm)
Aug 27, 2025
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability
Critical
CVE-2025-52122
was published
for
solspace/craft-freeform
(Composer)
Aug 27, 2025
devalue prototype pollution vulnerability
High
CVE-2025-57820
was published
for
devalue
(npm)
Aug 26, 2025
Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start
Moderate
GHSA-q77w-mwjj-7mqx
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python cProfile.run
Moderate
GHSA-49gj-c84q-6qm9
was published
for
picklescan
(pip)
Aug 26, 2025
Picklescan is missing detection when calling built-in python cProfile.runctx
Moderate
GHSA-9w88-8rmg-7g2p
was published
for
picklescan
(pip)
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API