GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,968
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,038
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,622 advisories
Filter by severity
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Low
GHSA-cf57-c578-7jvv
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Byaidu PDFMathTranslate vulnerable to open redirect
Low
CVE-2025-50736
was published
for
pdf2zh
(pip)
Oct 30, 2025
Drupal Umami Analytics allows Cross-Site Scripting (XSS)
Low
CVE-2025-10931
was published
for
drupal/umami_analytics
(Composer)
Oct 30, 2025
Keycloak allows access to admin path through flaw
Low
CVE-2025-10939
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Oct 28, 2025
Wasmtime vulnerable to segfault when using component resources
Low
CVE-2025-62711
was published
for
wasmtime
(Rust)
Oct 27, 2025
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Low
CVE-2025-55754
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2025-61795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
Low
CVE-2025-62255
was published
for
com.liferay:com.liferay.knowledge.base.web
(Maven)
Oct 23, 2025
Liferay Portal and DXP are Missing Authorization in Collection Provider
Low
CVE-2025-62247
was published
for
com.liferay:com.liferay.search.experiences.service
(Maven)
Oct 22, 2025
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
Low
CVE-2025-11966
was published
for
io.vertx:vertx-web
(Maven)
Oct 22, 2025
Borrowck Scarifices exposes uninitialized memory in any_as_u8_slice
Low
GHSA-xcpm-76hf-c9cc
was published
for
borrowck_sacrifices
(Rust)
Oct 22, 2025
Direct Ring Buffer has uninitialized memory exposure in create_ring_buffer
Low
GHSA-fp5x-7m4q-449f
was published
for
direct_ring_buffer
(Rust)
Oct 21, 2025
orx-pinned-vec has undefined behavior in index_of_ptr with empty slices
Low
GHSA-h5j3-crg5-8jqm
was published
for
orx-pinned-vec
(Rust)
Oct 21, 2025
uv has differential in tar extraction with PAX headers
Low
GHSA-w476-p2h3-79g9
was published
for
uv
(pip)
Oct 21, 2025
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to path traversal via Plugin upload
Low
GHSA-6wh5-mw9h-5c3w
was published
for
shopware/core
(Composer)
Oct 21, 2025
rollbar vulnerable to prototype pollution
Low
CVE-2025-57325
was published
for
rollbar
(npm)
Oct 20, 2025
TastyIgniter vulnerable to Cross-Site Scripting
Low
CVE-2025-61417
was published
for
tastyigniter/tastyigniter
(Composer)
Oct 20, 2025
Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
Low
CVE-2025-62505
was published
for
@lobehub/chat
(npm)
Oct 17, 2025
LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
Low
CVE-2025-62412
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
Low
CVE-2025-61924
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
Low
CVE-2025-61581
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Oct 16, 2025
Mattermost has an Observable Timing Discrepancy vulnerability
Low
CVE-2025-54499
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has an Incorrect Authorization vulnerability
Low
CVE-2025-10545
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
Low
CVE-2025-62380
was published
for
mailgen
(npm)
Oct 15, 2025
ProTip!
Advisories are also available from the
GraphQL API