GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,056
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,585 advisories
Filter by severity
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
High
CVE-2025-64439
was published
for
langgraph-checkpoint
(pip)
Nov 5, 2025
IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering
High
CVE-2025-64431
was published
for
github.com/zitadel/zitadel
(Go)
Nov 5, 2025
Liferay search widget vulnerable to Cross-site Scripting
Moderate
CVE-2025-43804
was published
for
com.liferay:com.liferay.portal.search
(Maven)
Sep 17, 2025
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
High
GHSA-wf5f-4jwr-ppcp
was published
for
pdfminer.six
(pip)
Nov 7, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Moderate
CVE-2025-57697
was published
for
AstrBot
(pip)
Nov 7, 2025
AstrBot contains a directory traversal vulnerability
High
CVE-2025-57698
was published
for
AstrBot
(pip)
Nov 7, 2025
Apollo Router Improperly Enforces Renamed Access Control Directives
High
CVE-2025-64347
was published
for
apollo-router
(Rust)
Nov 6, 2025
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
High
CVE-2025-64430
was published
for
parse-server
(npm)
Nov 5, 2025
Scrapy with Brotli is vulnerable to a denial of service (DoS) attack due to decompression
High
CVE-2025-6176
was published
for
Scrapy
(pip)
Oct 31, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write
High
CVE-2025-64324
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 7, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
Nuxt DevTools vulnerable to cross-site scripting (XSS)
Moderate
CVE-2025-52662
was published
for
@nuxt/devtools
(npm)
Nov 7, 2025
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Moderate
CVE-2025-64437
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Moderate
CVE-2025-58337
was published
for
doris-mcp-server
(pip)
Nov 5, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
flowise
(npm)
Oct 9, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
github.com/jaredallard/archives Has Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Moderate
CVE-2025-64346
was published
for
github.com/jaredallard/archives
(Go)
Mar 28, 2025
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Moderate
CVE-2025-64329
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
kgateway is missing xDS authorization
Moderate
CVE-2025-64323
was published
for
github.com/kgateway-dev/kgateway/v2
(Go)
Nov 4, 2025
ProTip!
Advisories are also available from the
GraphQL API