GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,614 advisories
Filter by severity
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
High
CVE-2025-64509
was published
for
bugsink
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
High
CVE-2025-64508
was published
for
bugsink
(pip)
Nov 13, 2025
Parse Server allows public `explain` queries which may expose sensitive database performance information and schema details
Moderate
CVE-2025-64502
was published
for
parse-server
(npm)
Nov 13, 2025
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
High
CVE-2025-64500
was published
for
symfony/http-foundation
(Composer)
Nov 12, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation
High
CVE-2025-64484
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Nov 12, 2025
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Low
CVE-2025-64345
was published
for
wasmtime
(Rust)
Nov 12, 2025
sudo-rs: Partial password reveal is possible after timeout
Low
CVE-2025-64170
was published
for
sudo-rs
(Rust)
Nov 12, 2025
OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed
High
CVE-2025-64099
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Nov 12, 2025
changedetection.io: Stored XSS in Watch update via API
Low
CVE-2025-62780
was published
for
changedetection.io
(pip)
Nov 12, 2025
Soft Serve is vulnerable to SSRF through its Webhooks
Critical
CVE-2025-64522
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
High
CVE-2025-64519
was published
for
torrentpier/torrentpier
(Composer)
Nov 10, 2025
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
High
CVE-2025-64518
was published
for
org.cyclonedx:cyclonedx-core-java
(Maven)
Nov 10, 2025
Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
High
CVE-2025-12613
was published
for
cloudinary
(npm)
Nov 10, 2025
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-vfpf-xmwh-8m65
was published
for
prosemirror_to_html
(RubyGems)
Nov 7, 2025
•
withdrawn
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
High
GHSA-f83h-ghpp-7wcc
was published
for
pdfminer.six
(pip)
Nov 7, 2025
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
High
GHSA-wf5f-4jwr-ppcp
was published
for
pdfminer.six
(pip)
Nov 7, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write
High
CVE-2025-64324
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 7, 2025
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Moderate
CVE-2025-57697
was published
for
AstrBot
(pip)
Nov 7, 2025
AstrBot contains a directory traversal vulnerability
High
CVE-2025-57698
was published
for
AstrBot
(pip)
Nov 7, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
CVE-2025-64495
was published
for
open-webui
(npm)
Nov 7, 2025
Nuxt DevTools vulnerable to cross-site scripting (XSS)
Moderate
CVE-2025-52662
was published
for
@nuxt/devtools
(npm)
Nov 7, 2025
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API