GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,629 advisories
Filter by severity
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
Suspended Directus user can continue to use session token to access API
Low
CVE-2025-30351
was published
for
@directus/api
(npm)
Mar 26, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
Cilium node based network policies may incorrectly allow workload traffic
Low
CVE-2025-30163
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Mar 24, 2025
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Low
CVE-2025-30162
was published
for
github.com/cilium/cilium
(Go)
Mar 24, 2025
AWS CDK CodePipeline: trusted entities are too broad
Low
GHSA-5pq3-h73f-66hr
was published
for
aws-cdk-lib
(npm)
Mar 24, 2025
Reflected XSS in go-httpbin due to unrestricted client control over Content-Type
Low
GHSA-528q-4pgm-wvg2
was published
for
github.com/mccutchen/go-httpbin
(Go)
Mar 21, 2025
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
Low
CVE-2025-27715
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Low
CVE-2025-29923
was published
for
github.com/redis/go-redis/v9
(Go)
Mar 20, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition
Low
CVE-2024-7598
was published
for
k8s.io/kubernetes/cmd/kube-apiserver
(Go)
Mar 20, 2025
Apache Seata Vulnerable to Deserialization of Untrusted Data
Low
CVE-2024-47552
was published
for
org.apache.seata:seata-config-core
(Maven)
Mar 20, 2025
Apache Seata Vulnerable to Data Amplification
Low
CVE-2024-54016
was published
for
org.apache.seata:seata-parent
(Maven)
Mar 20, 2025
Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
Low
CVE-2025-30197
was published
for
io.jenkins.plugins:zohoqengine
(Maven)
Mar 19, 2025
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Low
CVE-2025-1398
was published
for
mattermost-desktop
(npm)
Mar 17, 2025
Zincati allows unprivileged access to rpm-ostree D-Bus `Deploy()` and `FinalizeDeployment()` methods
Low
CVE-2025-27512
was published
for
zincati
(Rust)
Mar 17, 2025
Snowflake JDBC Driver client-side encryption key in DEBUG logs
Low
CVE-2025-27496
was published
for
net.snowflake:snowflake-jdbc
(Maven)
Mar 13, 2025
MODX allows cross-site scripting (XSS) via an SVG file
Low
CVE-2025-28010
was published
for
modx/revolution
(Composer)
Mar 13, 2025
Microweber vulnerable to XSS attack due to insure `group` component in its Settings handler
Low
CVE-2025-2214
was published
for
microweber/microweber
(Composer)
Mar 12, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
CVE-2025-27221
was published
for
uri
(RubyGems)
Mar 3, 2025
Magento LTS vulnerable to stored XSS in theme config fields
Low
CVE-2025-27400
was published
for
openmage/magento-lts
(Composer)
Mar 3, 2025
seajs Cross-site Scripting vulnerability
Low
CVE-2024-51091
was published
for
seajs
(npm)
Mar 3, 2025
ProTip!
Advisories are also available from the
GraphQL API