GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,656 advisories
Filter by severity
zx Uses Incorrectly-Resolved Name or Reference
Moderate
CVE-2025-13437
was published
for
zx
(npm)
Nov 20, 2025
OSV-SCALIBR has NULL Pointer Dereference
Low
CVE-2025-13425
was published
for
github.com/google/osv-scalibr
(Go)
Nov 20, 2025
md-to-pdf vulnerable to arbitrary JavaScript code execution when parsing front matter
Critical
CVE-2025-65108
was published
for
md-to-pdf
(npm)
Nov 20, 2025
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
High
CVE-2025-65106
was published
for
langchain-core
(pip)
Nov 20, 2025
@hpke/core reuses AEAD nonces
Critical
CVE-2025-64767
was published
for
@hpke/core
(npm)
Nov 20, 2025
@perfood/couch-auth may expose session tokens, passwords
Moderate
CVE-2025-60794
was published
for
@perfood/couch-auth
(npm)
Nov 20, 2025
phppgadmin contains an incorrect access control vulnerability
Moderate
CVE-2025-60799
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
phppgadmin contains a SQL injection vulnerability
Moderate
CVE-2025-60798
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
phppgadmin vulnerable to Cross-site Scripting
Low
CVE-2025-60796
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
Resty has a Path Traversal vulnerability
Low
CVE-2025-13435
was published
for
cn.dreampie:resty
(Maven)
Nov 20, 2025
phppgadmin contains a SQL injection vulnerability
Moderate
CVE-2025-60797
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read
Moderate
CVE-2025-47914
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption
Moderate
CVE-2025-58181
was published
for
golang.org/x/crypto
(Go)
Nov 19, 2025
OpenSTAManager has Authenticated SQL Injection in API via 'display' parameter
High
CVE-2025-65103
was published
for
devcode-it/openstamanager
(Composer)
Nov 19, 2025
Claude Code vulnerable to command execution prior to startup trust dialog
High
CVE-2025-65099
was published
for
@anthropic-ai/claude-code
(npm)
Nov 19, 2025
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Moderate
CVE-2025-65026
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
esm.sh CDN service has arbitrary file write via tarslip
High
CVE-2025-65025
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
Moderate
CVE-2025-65019
was published
for
astro
(npm)
Nov 19, 2025
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Moderate
CVE-2025-64765
was published
for
astro
(npm)
Nov 19, 2025
Astro vulnerable to reflected XSS via the server islands feature
High
CVE-2025-64764
was published
for
astro
(npm)
Nov 19, 2025
Astro Development Server has Arbitrary Local File Read
Low
CVE-2025-64757
was published
for
astro
(npm)
Nov 19, 2025
authentik's invitation expiry is delayed by at least 5 minutes
Moderate
CVE-2025-64708
was published
for
goauthentik.io
(Go)
Nov 19, 2025
authentik allows a deactivated Service account to authenticate to OAuth
Moderate
CVE-2025-64521
was published
for
goauthentik.io
(Go)
Nov 19, 2025
Apache Causeway vulnerable to deserialization in Java
Critical
CVE-2025-64408
was published
for
org.apache.causeway.commons:causeway-commons
(Maven)
Nov 19, 2025
MongoDB driver extension affected by mongoc_bulk_operation_t's read of invalid memory
Moderate
CVE-2025-12119
was published
for
mongodb/mongodb-extension
(Composer)
Nov 19, 2025
ProTip!
Advisories are also available from the
GraphQL API