GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,629 advisories
Filter by severity
Fiora chat group avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56515
was published
for
fiora
(npm)
Oct 1, 2025
Fiora chat user avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56514
was published
for
fiora
(npm)
Oct 1, 2025
vet MCP Server SSE Transport DNS Rebinding Vulnerability
Low
CVE-2025-59163
was published
for
github.com/safedep/vet
(Go)
Sep 29, 2025
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
Low
GHSA-q6hv-wcjr-wp8h
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 26, 2025
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Low
CVE-2025-59842
was published
for
jupyterlab
(pip)
Sep 26, 2025
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
Low
CVE-2025-1396
was published
for
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt
(Maven)
Sep 26, 2025
ml-logger deserialization vulnerability
Low
CVE-2025-10950
was published
for
ml-logger
(pip)
Sep 25, 2025
node-cube vulnerable to prototype pollution
Low
CVE-2025-57348
was published
for
node-cube
(npm)
Sep 24, 2025
magix-combine-ex vulnerable to prototype pollution
Low
CVE-2025-57321
was published
for
magix-combine-ex
(npm)
Sep 24, 2025
messageformat has a prototype pollution vulnerability
Low
CVE-2025-57349
was published
for
messageformat
(npm)
Sep 24, 2025
sassdoc-extras vulnerable to prototype pollution
Low
CVE-2025-57326
was published
for
sassdoc-extras
(npm)
Sep 24, 2025
web3-core-subscriptions has a Prototype Pollution vulnerability
Low
CVE-2025-57330
was published
for
web3-core-subscriptions
(npm)
Sep 24, 2025
toggle-array vulnerable to prototype pollution
Low
CVE-2025-57328
was published
for
toggle-array
(npm)
Sep 24, 2025
spmrc vulnerable to prototype pollution
Low
CVE-2025-57327
was published
for
spmrc
(npm)
Sep 24, 2025
web3-core-method is vulnerable to prototype pollution
Low
CVE-2025-57329
was published
for
web3-core-method
(npm)
Sep 24, 2025
Duplicate Advisory: rollbar vulnerable to prototype pollution
Low
GHSA-m929-rg27-gj99
was published
for
rollbar
(npm)
Sep 24, 2025
•
withdrawn
fast-redact vulnerable to prototype pollution
Low
CVE-2025-57319
was published
for
fast-redact
(npm)
Sep 24, 2025
Omni Wireguard SideroLink potential escape
Low
CVE-2025-59824
was published
for
github.com/siderolabs/omni
(Go)
Sep 24, 2025
Mangati NovoSGA XSS vulnerability in /admin
Low
CVE-2025-10909
was published
for
novosga/novosga
(Composer)
Sep 24, 2025
min-document vulnerable to prototype pollution
Low
CVE-2025-57352
was published
for
min-document
(npm)
Sep 24, 2025
GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-57407
was published
for
gp247/core
(Composer)
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
Low
CVE-2025-59546
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
GHSA-mm7x-qfjj-5g2c
was published
for
ammonia
(Rust)
Sep 22, 2025
Mattermost boards plugin fails to restrict download access to files
Low
CVE-2025-9081
was published
for
github.com/mattermost/mattermost-plugin-boards
(Go)
Sep 19, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
ProTip!
Advisories are also available from the
GraphQL API