GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,123
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,763 advisories
Filter by severity
Spring Expression language property modification using Spring Cloud Gateway Server WebFlux
Critical
CVE-2025-41243
was published
for
org.springframework.cloud:spring-cloud-gateway-server-webflux
(Maven)
Sep 16, 2025
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-10057
was published
Sep 17, 2025
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute...
High
Unreviewed
CVE-2025-54815
was published
Sep 19, 2025
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible...
High
Unreviewed
CVE-2025-57439
was published
Sep 22, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Tareq Hasan WP User...
Moderate
Unreviewed
CVE-2025-58673
was published
Sep 22, 2025
The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and...
Critical
Unreviewed
CVE-2025-9321
was published
Sep 23, 2025
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due...
Moderate
Unreviewed
CVE-2025-5717
was published
Sep 23, 2025
NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where...
High
Unreviewed
CVE-2025-23348
was published
Sep 24, 2025
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script...
High
Unreviewed
CVE-2025-23353
was published
Sep 24, 2025
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq...
High
Unreviewed
CVE-2025-23349
was published
Sep 24, 2025
NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script...
High
Unreviewed
CVE-2025-23354
was published
Sep 24, 2025
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-59251
was published
Sep 24, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2025-10993
was published
Sep 26, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce...
Moderate
Unreviewed
CVE-2025-60114
was published
Sep 26, 2025
j178/prek-action vulnerable to arbitrary code injection in composite action
Critical
GHSA-pwf7-47c3-mfhx
was published
for
j178/prek-action
(GitHub Actions)
Sep 29, 2025
This vulnerability affects Firefox < 143.0.3.
High
Unreviewed
CVE-2025-11153
was published
Sep 30, 2025
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
Critical
CVE-2025-61588
was published
for
risc0-aggregation
(Rust)
Oct 1, 2025
Dolibarr vulnerable to RCE via the computed field parameter
High
CVE-2025-56588
was published
for
dolibarr/dolibarr
(Composer)
Oct 1, 2025
Claude Code can execute commands prior to the startup trust dialog
High
CVE-2025-59536
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an...
Moderate
Unreviewed
CVE-2025-11344
was published
Oct 6, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript...
Moderate
Unreviewed
CVE-2025-42901
was published
Oct 14, 2025
An low privileged remote attacker with an account for the Web-based management can change the...
High
Unreviewed
CVE-2025-41699
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API