GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,068
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,678 advisories
Filter by severity
XWiki view file macro: User can view content of office file without view rights on the attachment
Moderate
CVE-2025-65089
was published
for
com.xwiki.pro:xwiki-pro-macros-ui
(Maven)
Nov 18, 2025
LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
Moderate
CVE-2025-65093
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
Critical
CVE-2025-65015
was published
for
joserfc
(pip)
Nov 18, 2025
LibreNMS has Weak Password Policy
Low
CVE-2025-65014
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`
Moderate
CVE-2025-65013
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Moderate
CVE-2025-65012
was published
for
getkirby/cms
(Composer)
Nov 18, 2025
XWiki AdminTools application doesn't set permissions on the AdminTools space
Moderate
CVE-2025-54990
was published
for
com.xwiki.admintools:application-admintools
(Maven)
Nov 18, 2025
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
High
GHSA-v5w9-prxf-w882
was published
for
flowise
(npm)
Nov 17, 2025
@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via welcome message
Moderate
CVE-2025-64758
was published
for
@dependencytrack/frontend
(npm)
Nov 17, 2025
glob CLI: Command injection via -c/--cmd executes matches with shell:true
High
CVE-2025-64756
was published
for
glob
(npm)
Nov 17, 2025
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
High
CVE-2025-62519
was published
for
phpmyfaq/phpmyfaq
(Composer)
Nov 17, 2025
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
High
CVE-2025-65073
was published
for
keystone
(pip)
Nov 17, 2025
lsFusion Platform has Path Traversal vulnerability
Moderate
CVE-2025-13262
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
vlife-base has Path Traversal vulnerability
Moderate
CVE-2025-13266
was published
for
io.github.wwwlike:vlife-base
(Maven)
Nov 17, 2025
lsFusion Platform has Path Traversal vulnerability
Moderate
CVE-2025-13261
was published
for
lsfusion.platform:web-client
(Maven)
Nov 17, 2025
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
Apollo Federation has Improper Enforcement of Access Control on Transitive Fields
High
GHSA-m8jr-fxqx-8xx6
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Directus is Vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-64747
was published
for
directus
(npm)
Nov 14, 2025
Directus has Improper Permission Handling on Deleted Fields
Moderate
CVE-2025-64746
was published
for
directus
(npm)
Nov 14, 2025
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
High
GHSA-jj37-3377-m6vv
was published
for
nodemailer
(npm)
Nov 14, 2025
•
withdrawn
ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
High
CVE-2025-64717
was published
for
github.com/zitadel/zitadel
(Go)
Nov 14, 2025
Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change
High
GHSA-fjh6-8679-9pch
was published
for
flowise-ui
(npm)
Nov 14, 2025
Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)
High
GHSA-x39m-3393-3qp4
was published
for
flowise-ui
(npm)
Nov 14, 2025
Flowise Fails to Invalidate Existing Sessions After Password Changes
High
GHSA-x7rp-qj2h-ghgw
was published
for
flowise
(npm)
Nov 14, 2025
ProTip!
Advisories are also available from the
GraphQL API