GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,713 advisories
Filter by severity
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
Low
GHSA-q6hv-wcjr-wp8h
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 26, 2025
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Low
CVE-2025-59842
was published
for
jupyterlab
(pip)
Sep 26, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18...
Low
Unreviewed
CVE-2025-5069
was published
Sep 26, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10868
was published
Sep 26, 2025
An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10871
was published
Sep 26, 2025
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
Low
CVE-2025-1396
was published
for
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt
(Maven)
Sep 26, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3...
Low
Unreviewed
CVE-2025-10867
was published
Sep 26, 2025
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for...
Low
Unreviewed
CVE-2025-10173
was published
Sep 26, 2025
A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the...
Low
Unreviewed
CVE-2025-10977
was published
Sep 26, 2025
A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown...
Low
Unreviewed
CVE-2025-10976
was published
Sep 26, 2025
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation...
Low
Unreviewed
CVE-2025-60019
was published
Sep 25, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
Rapid7 Appspider Pro versions below 7.5.021, suffer from a broken access control vulnerability in...
Low
Unreviewed
CVE-2025-36857
was published
Sep 25, 2025
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in...
Low
Unreviewed
CVE-2025-5494
was published
Sep 25, 2025
Ericsson
Indoor Connect 8855 contains a vulnerability where server-side security can be
bypassed...
Low
Unreviewed
CVE-2025-40838
was published
Sep 25, 2025
magix-combine-ex vulnerable to prototype pollution
Low
CVE-2025-57321
was published
for
magix-combine-ex
(npm)
Sep 24, 2025
messageformat has a prototype pollution vulnerability
Low
CVE-2025-57349
was published
for
messageformat
(npm)
Sep 24, 2025
sassdoc-extras vulnerable to prototype pollution
Low
CVE-2025-57326
was published
for
sassdoc-extras
(npm)
Sep 24, 2025
web3-core-subscriptions has a Prototype Pollution vulnerability
Low
CVE-2025-57330
was published
for
web3-core-subscriptions
(npm)
Sep 24, 2025
node-cube vulnerable to prototype pollution
Low
CVE-2025-57348
was published
for
node-cube
(npm)
Sep 24, 2025
toggle-array vulnerable to prototype pollution
Low
CVE-2025-57328
was published
for
toggle-array
(npm)
Sep 24, 2025
web3-core-method is vulnerable to prototype pollution
Low
CVE-2025-57329
was published
for
web3-core-method
(npm)
Sep 24, 2025
spmrc vulnerable to prototype pollution
Low
CVE-2025-57327
was published
for
spmrc
(npm)
Sep 24, 2025
Duplicate Advisory: rollbar vulnerable to prototype pollution
Low
GHSA-m929-rg27-gj99
was published
for
rollbar
(npm)
Sep 24, 2025
•
withdrawn
fast-redact vulnerable to prototype pollution
Low
CVE-2025-57319
was published
for
fast-redact
(npm)
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API