GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,972 advisories
Filter by severity
Taylored webhook validation vulnerabilities
Critical
GHSA-8g98-m4j9-qww5
was published
for
taylored
(npm)
Jun 18, 2025
OpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
Moderate
CVE-2025-50183
was published
for
@openlist-frontend/openlist-frontend
(npm)
Jun 18, 2025
Withdrawn Advisory: microlight allows a denial of service
Low
CVE-2025-45526
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
Withdrwn Advisory: microlight.js has a null pointer dereference vulnerability
Low
CVE-2025-45525
was published
for
microlight
(npm)
Jun 17, 2025
•
withdrawn
OpenNext for Cloudflare (opennextjs-cloudflare) has a SSRF vulnerability via /_next/image endpoint
High
CVE-2025-6087
was published
for
@opennextjs/cloudflare
(npm)
Jun 16, 2025
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
Critical
CVE-2025-49596
was published
for
@modelcontextprotocol/inspector
(npm)
Jun 13, 2025
pg-promise SQL Injection vulnerability
Moderate
CVE-2025-29744
was published
for
pg-promise
(npm)
Jun 12, 2025
Erxes Incorrect Access Control vulnerability
High
CVE-2024-57190
was published
for
erxes
(npm)
Jun 10, 2025
Erxes Path Traversal vulnerability
Moderate
CVE-2024-57189
was published
for
erxes
(npm)
Jun 10, 2025
taro-css-to-react-native Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5896
was published
for
taro-css-to-react-native
(npm)
Jun 9, 2025
@vue/cli-plugin-pwa Regular Expression Denial of Service vulnerability
Moderate
CVE-2025-5897
was published
for
@vue/cli-plugin-pwa
(npm)
Jun 9, 2025
brace-expansion Regular Expression Denial of Service vulnerability
Low
CVE-2025-5889
was published
for
brace-expansion
(npm)
Jun 9, 2025
pm2 Regular Expression Denial of Service vulnerability
Low
CVE-2025-5891
was published
for
pm2
(npm)
Jun 9, 2025
HaxCMS-PHP Command Injection Vulnerability
High
CVE-2025-49141
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability
Moderate
CVE-2025-49139
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
Multer vulnerable to Denial of Service via unhandled exception
High
CVE-2025-48997
was published
for
multer
(npm)
Jun 5, 2025
Unauthenticated Disclosure of PSU HAX CMS Site Listings via haxPsuUsage API Endpoint
Moderate
CVE-2025-48996
was published
for
@haxtheweb/open-apis
(npm)
Jun 5, 2025
NextJS-Auth0 SDK Vulnerable to CDN Caching of Session Cookies
High
CVE-2025-48947
was published
for
@auth0/nextjs-auth0
(npm)
Jun 4, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Moderate
CVE-2025-30360
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site
Moderate
CVE-2025-30359
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
AngularJS Incomplete Filtering of Special Elements vulnerability
Moderate
CVE-2025-2336
was published
for
angular-sanitize
(npm)
Jun 4, 2025
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function
Moderate
CVE-2025-5276
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
Markdownify MCP Server allows attackers to read arbitrary files
Moderate
CVE-2025-5273
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
ProTip!
Advisories are also available from the
GraphQL API