GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
21,070 advisories
Filter by severity
CVE-2025-0343: Swift ASN.1 can crash when parsing maliciously formed BER/DER
Low
CVE-2025-0343
was published
for
github.com/apple/swift-asn1
(Swift)
Jan 14, 2025
XWiki Realtime WYSIWYG Editor extension allows privilege escalation (PR) through realtime WYSIWYG editing
Critical
CVE-2025-23025
was published
for
org.xwiki.platform:xwiki-platform-realtime-wysiwyg-ui
(Maven)
Jan 14, 2025
Rasa Allows Remote Code Execution via Remote Model Loading
Critical
CVE-2024-49375
was published
for
rasa
(pip)
Jan 14, 2025
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
TYPO3 Indexed Search Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55923
was published
for
typo3/cms-indexed-search
(Composer)
Jan 14, 2025
TYPO3 Form Framework Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55922
was published
for
typo3/cms-form
(Composer)
Jan 14, 2025
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55921
was published
for
typo3/cms-extensionmanager
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Dashboard Module
Moderate
CVE-2024-55920
was published
for
typo3/cms-dashboard
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
TYPO3 Potential Open Redirect via Parsing Differences
Moderate
CVE-2024-55892
was published
for
typo3/cms-core
(Composer)
Jan 14, 2025
TYPO3 Information Disclosure via Exception Handling/Logger
Low
CVE-2024-55891
was published
for
typo3/cms-install
(Composer)
Jan 14, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2024-56323
was published
for
github.com/openfga/openfga
(Go)
Jan 13, 2025
Denial of Service in Keycloak Server via Security Headers
Moderate
CVE-2024-11734
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
Keycloak allows unrestricted admin use of system and environment variables
Moderate
CVE-2024-11736
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
jte's HTML templates containing Javascript template strings are subject to XSS
Moderate
CVE-2025-23026
was published
for
gg.jte:jte
(Maven)
Jan 13, 2025
The Umbraco Heartcore headless client library uses a vulnerable Refit dependency package
Low
GHSA-mgr7-5782-6jh9
was published
for
Umbraco.Headless.Client.Net
(NuGet)
Jan 13, 2025
notation-go's timestamp signature generation lacks certificate revocation check
Moderate
CVE-2024-56138
was published
for
github.com/notaryproject/notation-go
(Go)
Jan 13, 2025
notation-go has an OS error when setting CRL cache leads to denial of signature verification
Low
CVE-2024-51491
was published
for
github.com/notaryproject/notation-go
(Go)
Jan 13, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33299
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33298
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33297
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Low
CVE-2024-55226
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden vulnerable to user impersonation
High
CVE-2024-55225
was published
for
vaultwarden
(Rust)
Jan 9, 2025
ProTip!
Advisories are also available from the
GraphQL API