GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,600 advisories
Filter by severity
JDBC Driver for SQL Server has improper input validation issue
High
CVE-2025-59250
was published
for
com.microsoft.sqlserver:mssql-jdbc
(Maven)
Oct 14, 2025
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55247 | .NET Denial of Service Vulnerability
High
GHSA-q8g5-rw97-f55h
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
Oct 14, 2025
•
withdrawn
Duplicate Advisory: Microsoft Security Advisory CVE-2025-55248: .NET Information Disclosure Vulnerability
Moderate
GHSA-987x-96fq-9384
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Oct 14, 2025
•
withdrawn
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Apache Geode web-api is vulnerable to Cross-site Scripting
Moderate
CVE-2024-44088
was published
for
org.apache.geode:geode-web-api
(Maven)
Oct 14, 2025
Liferay has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-62251
was published
for
com.liferay:com.liferay.site.navigation.menu.item.asset.vocabulary
(Maven)
Oct 14, 2025
LibreNMS is vulnerable to Reflected-XSS in `report_this` function
Moderate
CVE-2025-62365
was published
for
librenms/librenms
(Composer)
Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62242
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Mentions Web is Vulnerable to Cross-site Scripting
Moderate
CVE-2025-62246
was published
for
com.liferay:com.liferay.mentions.web
(Maven)
Oct 13, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62252
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 13, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
llama-index has Insecure Temporary File
High
CVE-2025-7707
was published
for
llama-index
(pip)
Oct 13, 2025
Liferay Publications is vulnerable to Incorrect Authorization
Moderate
CVE-2025-62243
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62244
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
High
CVE-2025-11695
was published
for
mongodb
(Rust)
Oct 13, 2025
CommandKit has incorrect command name exposure in context object for message command aliases
Moderate
CVE-2025-62378
was published
for
commandkit
(npm)
Oct 13, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
QGIS QWC2 Cross-Site Scripting vulnerability
Moderate
CVE-2025-11183
was published
for
qwc2
(npm)
Oct 13, 2025
cel-rust May Panic During Parsing of Invalid CEL Expressions
High
CVE-2025-62162
was published
for
cel
(Rust)
Oct 11, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
Parallax is vulnerable to DoS via malicious p2p message
High
GHSA-xc79-566c-j4qx
was published
for
github.com/microstack-tech/parallax
(Go)
Oct 10, 2025
Astro's `X-Forwarded-Host` is reflected without validation
Moderate
CVE-2025-61925
was published
for
astro
(npm)
Oct 10, 2025
ProTip!
Advisories are also available from the
GraphQL API