GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,614 advisories
Filter by severity
Cross-site Scripting (XSS) in serialize-javascript
Moderate
CVE-2024-11831
was published
for
serialize-javascript
(npm)
Feb 10, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
High
CVE-2025-64509
was published
for
bugsink
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
High
CVE-2025-64508
was published
for
bugsink
(pip)
Nov 13, 2025
Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details
Moderate
CVE-2025-64502
was published
for
parse-server
(npm)
Nov 13, 2025
Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
High
CVE-2025-12613
was published
for
cloudinary
(npm)
Nov 10, 2025
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
High
CVE-2025-64500
was published
for
symfony/http-foundation
(Composer)
Nov 12, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation
High
CVE-2025-64484
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Nov 12, 2025
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Low
CVE-2025-64345
was published
for
wasmtime
(Rust)
Nov 12, 2025
sudo-rs: Partial password reveal is possible after timeout
Low
CVE-2025-64170
was published
for
sudo-rs
(Rust)
Nov 12, 2025
OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed
High
CVE-2025-64099
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Nov 12, 2025
changedetection.io: Stored XSS in Watch update via API
Low
CVE-2025-62780
was published
for
changedetection.io
(pip)
Nov 12, 2025
Keycloak vulnerable to session takeovers due to reuse of session identifiers
Moderate
CVE-2025-12390
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 28, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
Moderate
CVE-2025-64437
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
CVE-2025-64495
was published
for
open-webui
(npm)
Nov 7, 2025
Soft Serve is vulnerable to SSRF through its Webhooks
Critical
CVE-2025-64522
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 10, 2025
pimcore/admin-ui-classic-bundle Unverified Password Change
Moderate
CVE-2023-5844
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Oct 31, 2023
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
High
CVE-2025-64519
was published
for
torrentpier/torrentpier
(Composer)
Nov 10, 2025
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
High
CVE-2025-64518
was published
for
org.cyclonedx:cyclonedx-core-java
(Maven)
Nov 10, 2025
expr-eval does not restrict functions passed to the evaluate function
High
CVE-2025-12735
was published
for
expr-eval
(npm)
Nov 5, 2025
Magento affected by a server-side denial-of-service using a GraphQL field
High
CVE-2021-36044
was published
for
magento/community-edition
(Composer)
May 24, 2022
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-vfpf-xmwh-8m65
was published
for
prosemirror_to_html
(RubyGems)
Nov 7, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API