GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,545 advisories
Filter by severity
motionEye vulnerable to RCE via unsanitized motion config parameter
High
CVE-2025-60787
was published
for
motioneye
(pip)
Nov 3, 2025
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
High
CVE-2025-47776
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Agno session state overwrites between different sessions/users
High
CVE-2025-64168
was published
for
agno
(pip)
Oct 31, 2025
Scrapy with Brotli is vulnerable to a denial of service (DoS) attack due to decompression
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
sqls-server/sqls is vulnerable to command injection in the config command
High
CVE-2025-61141
was published
for
github.com/sqls-server/sqls
(Go)
Oct 30, 2025
Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12060
was published
for
keras
(pip)
Oct 30, 2025
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
High
CVE-2025-64112
was published
for
statamic/cms
(Composer)
Oct 30, 2025
gnark-crypto allows unchecked memory allocation during vector deserialization
High
GHSA-fj2x-735w-74vq
was published
for
github.com/consensys/gnark-crypto
(Go)
Oct 30, 2025
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
High
CVE-2025-62726
was published
for
n8n
(npm)
Oct 30, 2025
Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass
High
CVE-2025-12466
was published
for
drupal/simple_oauth
(Composer)
Oct 30, 2025
Drupal Acquia DAM allows Forceful Browsing
High
CVE-2025-9954
was published
for
drupal/acquia_dam
(Composer)
Oct 30, 2025
Drupal CivicTheme Design System allows Forceful Browsing
High
CVE-2025-12082
was published
for
drupal/civictheme
(Composer)
Oct 30, 2025
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
High
CVE-2025-64104
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 29, 2025
Zitadel May Bypass Second Authentication Factor
High
CVE-2025-64103
was published
for
github.com/zitadel/zitadel
(Go)
Oct 29, 2025
Zitadel allows brute-forcing authentication factors
High
CVE-2025-64102
was published
for
github.com/zitadel/zitadel
(Go)
Oct 29, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
MLflow Weak Password Requirements Authentication Bypass Vulnerability
High
CVE-2025-11200
was published
for
mlflow
(pip)
Oct 29, 2025
TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update
High
CVE-2025-60542
was published
for
typeorm
(npm)
Oct 29, 2025
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
High
GHSA-c2jp-c369-7pvx
was published
for
fastmcp
(pip)
Oct 29, 2025
Jenkins SAML Plugin does not implement a replay cache
High
CVE-2025-64131
was published
for
org.jenkins-ci.plugins:saml
(Maven)
Oct 29, 2025
Jenkins Azure CLI Plugin does not restrict the commands it executes
High
CVE-2025-64140
was published
for
org.jenkins-ci.plugins:azure-cli
(Maven)
Oct 29, 2025
Jenkins JDepend Plugin vulnerable to XML external entity attacks
High
CVE-2025-64134
was published
for
org.jenkins-ci.plugins:jdepend
(Maven)
Oct 29, 2025
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
High
CVE-2025-62727
was published
for
starlette
(pip)
Oct 28, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
ProTip!
Advisories are also available from the
GraphQL API