GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,656 advisories
Filter by severity
pypdf's LZWDecode streams be manipulated to exhaust RAM
Moderate
CVE-2025-66019
was published
for
pypdf
(pip)
Nov 24, 2025
Formwork CMS has Stored Cross-Site Scripting Vulnerebility in Blog Tags
Moderate
CVE-2025-65956
was published
for
getformwork/formwork
(Composer)
Nov 24, 2025
Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true`
Moderate
CVE-2025-65944
was published
for
@sentry/astro
(npm)
Nov 24, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
High
CVE-2025-64761
was published
for
github.com/openbao/openbao
(Go)
Nov 24, 2025
new-api is vulnerable to SSRF Bypass
High
CVE-2025-62155
was published
for
github.com/QuantumNous/new-api
(Go)
Nov 24, 2025
Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices
High
CVE-2025-13609
was published
for
keylime
(pip)
Nov 24, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
Free5GC is vulnerable to DoS through its Npcf_BDTPolicyControl POST API
Moderate
CVE-2025-60632
was published
for
github.com/free5gc/pcf
(Go)
Nov 24, 2025
Free5GC is vulnerable to DoS via the Nudm_SubscriberDataManagement API
Moderate
CVE-2025-60633
was published
for
github.com/free5gc/openapi
(Go)
Nov 24, 2025
Apache Syncope's AES encryption stores hard-coded passwords in internal database
High
CVE-2025-65998
was published
for
org.apache.syncope:syncope-core
(Maven)
Nov 24, 2025
thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
High
CVE-2025-65947
was published
for
thread-amount
(Rust)
Nov 21, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
Low
CVE-2025-65111
was published
for
github.com/authzed/spicedb
(Go)
Nov 21, 2025
MLX has Wild Pointer Dereference in load_gguf()
Moderate
CVE-2025-62609
was published
for
mlx
(pip)
Nov 21, 2025
MLX has heap-buffer-overflow in load()
Moderate
CVE-2025-62608
was published
for
mlx
(pip)
Nov 21, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
Grafana Incorrect Privilege Assignment vulnerability
Critical
CVE-2025-41115
was published
for
github.com/grafana/grafana
(Go)
Nov 21, 2025
OpenFGA Improper Policy Enforcement
Moderate
CVE-2025-64751
was published
for
github.com/openfga/openfga
(Go)
Nov 20, 2025
Minder does not sandbox http.send in Rego programs
High
GHSA-6xvf-4vh9-mw47
was published
for
github.com/mindersec/minder
(Go)
Nov 20, 2025
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Moderate
CVE-2025-63700
was published
for
@clerk/clerk-js
(npm)
Nov 20, 2025
authkit-nextjs may let session cookies be cached in CDNs
High
CVE-2025-64762
was published
for
@workos-inc/authkit-nextjs
(npm)
Nov 20, 2025
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
High
CVE-2025-64755
was published
for
@anthropic-ai/claude-code
(npm)
Nov 20, 2025
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
Moderate
CVE-2025-62426
was published
for
vllm
(pip)
Nov 20, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
High
CVE-2025-62372
was published
for
vllm
(pip)
Nov 20, 2025
vLLM deserialization vulnerability leading to DoS and potential RCE
High
CVE-2025-62164
was published
for
vllm
(pip)
Nov 20, 2025
Snipe-IT has Cross-site Scripting vulnerability in CSV import workflow
Moderate
CVE-2025-64027
was published
for
snipe/snipe-it
(Composer)
Nov 20, 2025
ProTip!
Advisories are also available from the
GraphQL API