GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,253 advisories
Filter by severity
pg-promise SQL Injection vulnerability
Moderate
CVE-2025-29744
was published
for
pg-promise
(npm)
Jun 12, 2025
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
Moderate
CVE-2025-50183
was published
for
@openlist-frontend/openlist-frontend
(npm)
Jun 18, 2025
Erxes Path Traversal vulnerability
Moderate
CVE-2024-57189
was published
for
erxes
(npm)
Jun 10, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
taro-css-to-react-native Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5896
was published
for
taro-css-to-react-native
(npm)
Jun 9, 2025
@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability
Moderate
CVE-2025-49139
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
AngularJS Incomplete Filtering of Special Elements vulnerability
Moderate
CVE-2025-2336
was published
for
angular-sanitize
(npm)
Jun 4, 2025
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
Moderate
CVE-2025-48996
was published
for
@haxtheweb/open-apis
(npm)
Jun 5, 2025
Cross-site Scripting (XSS) in serialize-javascript
Moderate
CVE-2024-11831
was published
for
serialize-javascript
(npm)
Feb 10, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Moderate
CVE-2025-30360
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site
Moderate
CVE-2025-30359
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
Strapi allows Server-Side Request Forgery in Webhook function
Moderate
CVE-2024-52588
was published
for
@strapi/admin
(npm)
May 27, 2025
Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function
Moderate
CVE-2025-5276
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
Markdownify MCP Server allows attackers to read arbitrary files
Moderate
CVE-2025-5273
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
Remote code execution via the `pretty` option.
Moderate
CVE-2021-21353
was published
for
pug
(npm)
Mar 3, 2021
IPC messages delivered to the wrong frame in Electron
Moderate
CVE-2020-26272
was published
for
electron
(npm)
Jan 28, 2021
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Moderate
CVE-2018-25110
was published
for
marked
(npm)
May 23, 2025
radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Moderate
CVE-2025-48054
was published
for
radashi
(npm)
May 27, 2025
Cocotais Bot has builtin .echo command injection
Moderate
CVE-2025-47948
was published
for
cocotais-bot
(npm)
May 19, 2025
lockfile-lint-api Vulnerable to Incorrect Behavior Order
Moderate
CVE-2025-4759
was published
for
lockfile-lint-api
(npm)
May 16, 2025
Meteor Affected By Inefficient Regular Expression Complexity
Moderate
CVE-2025-4727
was published
for
meteor
(npm)
May 16, 2025
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
Moderate
CVE-2024-34343
was published
for
nuxt
(npm)
Aug 5, 2024
Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
Moderate
CVE-2025-47204
was published
for
bootstrap-multiselect
(npm)
May 13, 2025
@lumieducation/h5p-server Fails to Sanitize Plain Text Strings
Moderate
CVE-2025-47828
was published
for
@lumieducation/h5p-server
(npm)
May 11, 2025
@misskey-dev/summaly allows IP Filter Bypass via Redirect
Moderate
GHSA-jqx4-9gpq-rppm
was published
for
@misskey-dev/summaly
(npm)
May 6, 2025
ProTip!
Advisories are also available from the
GraphQL API