GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
21,070 advisories
Filter by severity
Crayfish allows Remote Code Execution via Homarus Authorization header
Critical
GHSA-mm6v-68qp-f9fw
was published
for
islandora/crayfish
(Composer)
Jan 15, 2025
SP1 has missing verifier checks and fiat-shamir observations
High
GHSA-c873-wfhp-wx5m
was published
for
sp1-stark
(Rust)
Jan 15, 2025
Sentry's improper authentication on SAML SSO process allows user impersonation
Critical
CVE-2025-22146
was published
for
sentry
(pip)
Jan 15, 2025
Insecure Temporary File in RESTEasy
Moderate
CVE-2023-0482
was published
for
org.jboss.resteasy:resteasy-core
(Maven)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20086
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost Incorrect Type Conversion or Cast
Moderate
CVE-2025-21088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-mqf3-qpc3-g26q
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS in form messages
Moderate
CVE-2024-53277
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS via insert media remote file oembed
Moderate
CVE-2024-47605
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Lodestar snappy checksum issue
Low
GHSA-m9c9-mc2h-9wjw
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
Lodestar snappy decompression issue
Low
GHSA-53rv-hcvm-rpp9
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
Rancher UI has Stored Cross-site Scripting vulnerability
High
CVE-2024-52281
was published
for
github.com/rancher/rancher
(Go)
Jan 14, 2025
Django has a potential denial-of-service vulnerability in IPv6 validation
Moderate
CVE-2024-56374
was published
for
Django
(pip)
Jan 14, 2025
Git LFS permits exfiltration of credentials via crafted HTTP URLs
High
CVE-2024-53263
was published
for
github.com/git-lfs/git-lfs
(Go)
Jan 14, 2025
Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21176
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability
High
CVE-2025-21172
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability
High
CVE-2025-21171
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
Moderate
CVE-2025-23041
was published
for
Umbraco.Forms
(NuGet)
Jan 14, 2025
Git Credential Manager carriage-return character in remote URL allows malicious repository to leak credentials
High
CVE-2024-50338
was published
for
git-credential-manager
(NuGet)
Jan 14, 2025
Wildfly HAL Console Cross-Site Scripting
Moderate
CVE-2025-23366
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
Mediawiki - DataTransfer Extension Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS)
Moderate
CVE-2025-23081
was published
for
mediawiki/data-transfer
(Composer)
Jan 14, 2025
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Moderate
CVE-2024-45627
was published
for
org.apache.linkis:linkis-metadata-query-service-jdbc
(Maven)
Jan 14, 2025
Vyper Does Not Check the Success of Certain Precompile Calls
Low
CVE-2025-21607
was published
for
vyper
(pip)
Jan 14, 2025
Gradio Blocked Path ACL Bypass Vulnerability
Critical
CVE-2025-23042
was published
for
gradio
(pip)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API