GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,698 advisories
Filter by severity
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
/etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4:...
Low
Unreviewed
CVE-2025-12603
was published
Nov 1, 2025
/etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1...
Low
Unreviewed
CVE-2025-12602
was published
Nov 1, 2025
A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The...
Low
Unreviewed
CVE-2025-58469
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a...
Low
Unreviewed
CVE-2025-58465
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote...
Low
Unreviewed
CVE-2025-54168
was published
Nov 7, 2025
An allocation of resources without limits or throttling vulnerability has been reported to affect...
Low
Unreviewed
CVE-2025-53411
was published
Nov 7, 2025
A relative path traversal vulnerability has been reported to affect Download Station. If a remote...
Low
Unreviewed
CVE-2025-58463
was published
Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-52865
was published
Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-53412
was published
Nov 7, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a...
Low
Unreviewed
CVE-2025-57706
was published
Nov 7, 2025
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote...
Low
Unreviewed
CVE-2025-53408
was published
Nov 7, 2025
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to...
Low
Unreviewed
CVE-2025-11219
was published
Nov 7, 2025
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU...
Low
Unreviewed
CVE-2025-12221
was published
Oct 25, 2025
Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass...
Low
Unreviewed
CVE-2025-8558
was published
Nov 3, 2025
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Low
CVE-2025-64326
was published
for
weblate
(pip)
Nov 5, 2025
A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been declared as...
Low
Unreviewed
CVE-2025-2349
was published
Mar 17, 2025
min-document vulnerable to prototype pollution
Low
CVE-2025-57352
was published
for
min-document
(npm)
Sep 24, 2025
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
Low
GHSA-w2jf-268q-mrvh
was published
for
github.com/opentofu/opentofu
(Go)
Nov 6, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Low
GHSA-cf57-c578-7jvv
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Apereo CAS code injection vulnerability
Low
CVE-2025-3984
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and...
Low
Unreviewed
CVE-2025-43423
was published
Nov 4, 2025
A denial-of-service issue was addressed with improved input validation. This issue is fixed in...
Low
Unreviewed
CVE-2025-43365
was published
Nov 4, 2025
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2025-61795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
ProTip!
Advisories are also available from the
GraphQL API