GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,458
Erlang
33
GitHub Actions
22
Go
2,156
Maven
5,000+
npm
3,818
NuGet
693
pip
3,497
Pub
12
RubyGems
903
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,433 advisories
Filter by severity
Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality
Moderate
CVE-2025-0660
was published
for
concrete5/concrete5
(Composer)
Mar 10, 2025
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
Moderate
CVE-2025-1391
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 10, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Mar 10, 2025
PocketMine-MP allows malicious client data to waste server resources due to lack of limits for explode()
Moderate
GHSA-g274-c6jj-h78p
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 10, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality
Moderate
CVE-2024-52812
was published
for
github.com/lf-edge/ekuiper
(Go)
Mar 10, 2025
Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs
Moderate
CVE-2025-1296
was published
for
github.com/hashicorp/nomad
(Go)
Mar 10, 2025
LocalS3 XML Parser Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-47qw-ccjm-9c2c
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API
Moderate
GHSA-v232-254c-m6p7
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-2466-4485-4pxj
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1944
was published
for
picklescan
(pip)
Mar 10, 2025
Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
CVE-2025-1945
was published
for
picklescan
(pip)
Mar 10, 2025
LocalS3 CreateBucketConfiguration Endpoint XML External Entity (XXE) Injection
Moderate
CVE-2025-27136
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
Duplicate Advisory: Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-2fh4-gpch-vqv4
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Laravel framework susceptible to reflected cross-site scripting
Moderate
CVE-2024-13919
was published
for
laravel/framework
(Composer)
Mar 10, 2025
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Moderate
GHSA-w6mr-mj53-x258
was published
for
picklescan
(pip)
Mar 10, 2025
•
withdrawn
Laravel framework susceptible to reflected cross-site scripting
Moderate
CVE-2024-13918
was published
for
laravel/framework
(Composer)
Mar 10, 2025
Apache Camel: Camel Message Header Injection via Improper Filtering
Moderate
CVE-2025-27636
was published
for
org.apache.camel:camel-support
(Maven)
Mar 9, 2025
qcp has possible crash/DOS in some build configurations
Moderate
GHSA-fmwf-c46w-r8qm
was published
for
qcp
(Rust)
Mar 8, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
GHSA-2gh3-rmm4-6rq5
was published
for
protobuf
(Rust)
Mar 7, 2025
Some AES functions may panic when overflow checking is enabled in ring
Moderate
GHSA-4p46-pwfr-66x6
was published
for
ring
(Rust)
Mar 7, 2025
Django vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-26699
was published
for
Django
(pip)
Mar 6, 2025
Envoy Gateway Log Injection Vulnerability
Moderate
CVE-2025-25294
was published
for
github.com/envoyproxy/gateway
(Go)
Mar 6, 2025
NocoDB Vulnerable to Reflected Cross-Site Scripting on Reset Password Page
Moderate
CVE-2025-27506
was published
for
nocodb
(npm)
Mar 6, 2025
ray vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-1979
was published
for
ray
(pip)
Mar 6, 2025
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
Moderate
CVE-2025-27623
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 6, 2025
ProTip!
Advisories are also available from the
GraphQL API