GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
36
GitHub Actions
29
Go
2,336
Maven
5,000+
npm
3,970
NuGet
713
pip
3,767
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
8,067 advisories
Filter by severity
Apache Tomcat - DoS in multipart upload
High
CVE-2025-48988
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
microlight.js has a null pointer dereference vulnerability
High
CVE-2025-45525
was published
for
microlight
(npm)
Jun 17, 2025
Gradio allows credential leakage on Windows
High
CVE-2024-34510
was published
for
gradio
(pip)
May 5, 2024
Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability
High
CVE-2025-30399
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jun 11, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
OpenNext for Cloudflare (opennextjs-cloudflare) has a SSRF vulnerability via /_next/image endpoint
High
CVE-2025-6087
was published
for
@opennextjs/cloudflare
(npm)
Jun 16, 2025
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
High
CVE-2025-48976
was published
for
org.apache.commons:commons-fileupload2-core
(Maven)
Jun 16, 2025
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
High
CVE-2025-3594
was published
for
com.liferay:com.liferay.server.admin.web
(Maven)
Jun 16, 2025
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
High
CVE-2025-3526
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Jun 16, 2025
Liferay Portal does not limit the depth of a GraphQL queries
High
CVE-2025-3602
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Jun 16, 2025
protobuf-python has a potential Denial of Service issue
High
CVE-2025-4565
was published
for
protobuf
(pip)
Jun 16, 2025
Regular Expression Denial of Service in papaparse
High
CVE-2020-36649
was published
for
papaparse
(npm)
Sep 4, 2020
Duplicate Advisory: PapaParse Inefficient Regular Expression Complexity vulnerability
High
GHSA-798h-g4j5-5537
was published
for
papaparse
(npm)
Jan 11, 2023
•
withdrawn
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
High
CVE-2025-26646
was published
for
Microsoft.Build.Tasks.Core
(NuGet)
May 13, 2025
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
High
CVE-2025-48957
was published
for
astrbot
(pip)
Jun 4, 2025
Salt vulnerable to arbitrary event injection
High
CVE-2025-22239
was published
for
salt
(pip)
Jun 13, 2025
Salt has minion event bus authorization bypass vulnerability
High
CVE-2025-22236
was published
for
salt
(pip)
Jun 13, 2025
XWiki does not require right warnings for XClass definitions
High
CVE-2025-49585
was published
for
org.xwiki.platform:xwiki-platform-security-requiredrights-default
(Maven)
Jun 13, 2025
XWiki allows remote code execution through preview of XClass changes in AWM editor
High
CVE-2025-49586
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 13, 2025
pgx SQL Injection via Line Comment Creation
High
CVE-2024-27289
was published
for
github.com/jackc/pgx
(Go)
Mar 4, 2024
XWiki makes title of inaccessible pages available through the class property values REST API
High
CVE-2025-49584
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 13, 2025
XWiki allows remote code execution through default value of wiki macro wiki-type parameters
High
CVE-2025-49581
was published
for
org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
(Maven)
Jun 13, 2025
XWiki's required right warnings for macros are incomplete
High
CVE-2025-49582
was published
for
org.xwiki.platform:xwiki-platform-rendering-macro-cache
(Maven)
Jun 13, 2025
XWiki allows privilege escalation through link refactoring
High
CVE-2025-49580
was published
for
org.xwiki.platform:xwiki-platform-refactoring-default
(Maven)
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API