GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,412
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,649
Pub
13
RubyGems
1,027
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,430 advisories
Filter by severity
Altcha Proof-of-Work obfuscation mode cryptanalytic break
Moderate
CVE-2025-65849
was published
for
altcha
(npm)
Dec 8, 2025
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
Moderate
CVE-2025-66469
was published
for
nicegui
(pip)
Dec 8, 2025
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
Critical
CVE-2025-65964
was published
for
n8n
(npm)
Dec 8, 2025
memos vulnerability allows the creation of arbitrary accounts
High
CVE-2025-65795
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos lacks file name validation or verification
Moderate
CVE-2025-65799
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily modification or deletion registered identity providers
Moderate
CVE-2025-65797
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily reactions deletion
Moderate
CVE-2025-65796
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily modification or deletion of attachments
Moderate
CVE-2025-65798
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Moderate
CVE-2025-66578
was published
for
robrichards/xmlseclibs
(Composer)
Dec 8, 2025
Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
Critical
CVE-2025-66565
was published
for
github.com/gofiber/utils
(Go)
Dec 8, 2025
1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers
Moderate
CVE-2025-66508
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Moderate
CVE-2025-66491
was published
for
github.com/traefik/traefik/v3
(Go)
Dec 8, 2025
Path Normalization Bypass in Traefik Router + Middleware Rules
Moderate
CVE-2025-66490
was published
for
github.com/traefik/traefik
(Go)
Dec 8, 2025
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Moderate
CVE-2025-66202
was published
for
astro
(npm)
Dec 8, 2025
Withdrawn Advisory: Emby Server API Vulnerability allowing to gain administrative access without precondition
Critical
CVE-2025-64113
was published
for
MediaBrowser.Server.Core
(NuGet)
Dec 8, 2025
•
withdrawn
Langflow CORS misconfiguration enables Account Takeover and RCE
Critical
CVE-2025-34291
was published
for
langflow
(pip)
Dec 6, 2025
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
nitro-tpm-pcr-compute may allow kernel command line modification by an account operator
Moderate
GHSA-xrv8-2pf5-f3q7
was published
for
nitro-tpm-pcr-compute
(Rust)
Dec 5, 2025
yawkat LZ4 Java has a possible information leak in Java safe decompressor
High
CVE-2025-66566
was published
for
at.yawk.lz4:lz4-java
(Maven)
Dec 5, 2025
Sigstore Timestamp Authority allocates excessive memory during request parsing
High
CVE-2025-66564
was published
for
github.com/sigstore/timestamp-authority
(Go)
Dec 5, 2025
Fulcio allocates excessive memory during token parsing
High
CVE-2025-66506
was published
for
github.com/sigstore/fulcio
(Go)
Dec 5, 2025
urllib3 streaming API improperly handles highly compressed data
High
CVE-2025-66471
was published
for
urllib3
(pip)
Dec 5, 2025
urllib3 allows an unbounded number of links in the decompression chain
High
CVE-2025-66418
was published
for
urllib3
(pip)
Dec 5, 2025
Envoy's TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Moderate
CVE-2025-66220
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
ProTip!
Advisories are also available from the
GraphQL API