GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,760 advisories
Filter by severity
Improper Control of Generation of Code ('Code Injection') vulnerability in Laborator Kalium...
High
Unreviewed
CVE-2025-49926
was published
Oct 22, 2025
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept...
Moderate
Unreviewed
CVE-2025-8848
was published
Oct 22, 2025
An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker...
High
Unreviewed
CVE-2025-61488
was published
Oct 20, 2025
Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
GHSA-3g4j-r53p-22wx
was published
for
flowise
(npm)
Oct 17, 2025
•
withdrawn
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically...
Critical
Unreviewed
CVE-2025-57567
was published
Oct 17, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-11905
was published
Oct 17, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain...
Critical
Unreviewed
CVE-2025-11548
was published
Oct 14, 2025
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in...
Moderate
Unreviewed
CVE-2025-31365
was published
Oct 14, 2025
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An...
Critical
Unreviewed
CVE-2025-46581
was published
Oct 14, 2025
An low privileged remote attacker with an account for the Web-based management can change the...
High
Unreviewed
CVE-2025-41699
was published
Oct 14, 2025
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript...
Moderate
Unreviewed
CVE-2025-42901
was published
Oct 14, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an...
Moderate
Unreviewed
CVE-2025-11344
was published
Oct 6, 2025
Claude Code can execute commands prior to the startup trust dialog
High
CVE-2025-59536
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
Dolibarr vulnerable to RCE via the computed field parameter
High
CVE-2025-56588
was published
for
dolibarr/dolibarr
(Composer)
Oct 1, 2025
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
Critical
CVE-2025-61588
was published
for
risc0-aggregation
(Rust)
Oct 1, 2025
This vulnerability affects Firefox < 143.0.3.
High
Unreviewed
CVE-2025-11153
was published
Sep 30, 2025
j178/prek-action vulnerable to arbitrary code injection in composite action
Critical
GHSA-pwf7-47c3-mfhx
was published
for
j178/prek-action
(GitHub Actions)
Sep 29, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce...
Moderate
Unreviewed
CVE-2025-60114
was published
Sep 26, 2025
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2025-10993
was published
Sep 26, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-59251
was published
Sep 24, 2025
NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where...
High
Unreviewed
CVE-2025-23348
was published
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API