GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,781
NuGet
681
pip
3,460
Pub
12
RubyGems
893
Rust
891
Swift
38
Unreviewed advisories
All unreviewed
5,000+
9,294 advisories
Filter by severity
Server-Side Request Forgery (SSRF) in activitypub_federation
Moderate
GHSA-7723-35v7-qcxw
was published
for
activitypub_federation
(Rust)
Feb 10, 2025
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
Denial of Service attack on windows app using Netty
Moderate
CVE-2025-25193
was published
for
io.netty:netty-common
(Maven)
Feb 10, 2025
grcov has an out of bounds write triggered by crafted coverage data
Moderate
GHSA-qm2p-4w45-v2vr
was published
for
grcov
(Rust)
Feb 10, 2025
esbuild enables any website to send any requests to the development server and read the response
Moderate
GHSA-67mh-4wv8-2f99
was published
for
esbuild
(npm)
Feb 10, 2025
Hickory DNS's DNSSEC validation may accept broken authentication chains
Moderate
CVE-2025-25188
was published
for
hickory-proto
(Rust)
Feb 10, 2025
Possible DoS by memory exhaustion in net-imap
Moderate
CVE-2025-25186
was published
for
net-imap
(RubyGems)
Feb 10, 2025
Apache Felix Webconsole: XSS in services console
Moderate
CVE-2025-25247
was published
for
org.apache.felix:org.apache.felix.webconsole
(Maven)
Feb 10, 2025
Connect-CMS Access control vulnerability
Moderate
GHSA-5rjc-jc28-cwgg
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
xml2rfc has file inclusion irregularities
Moderate
GHSA-432c-wxpg-m4q3
was published
for
xml2rfc
(pip)
Feb 7, 2025
Pimcore Admin Classic Bundle allows user enumeration
Moderate
CVE-2025-24980
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Feb 7, 2025
Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
Moderate
CVE-2024-57610
was published
for
sylius/sylius
(Composer)
Feb 6, 2025
•
withdrawn
Apache James vulnerable to denial of service through JMAP HTML to text conversion
Moderate
CVE-2024-45626
was published
for
org.apache.james:james-server-jmap-draft
(Maven)
Feb 6, 2025
Plenti - Code Injection - Denial of Services
Moderate
GHSA-mj4v-hp69-27x5
was published
for
github.com/plentico/plenti
(Go)
Feb 5, 2025
Keycloak on Quarkus CLI option for encrypted JGroups ignored
Moderate
CVE-2024-10973
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Feb 5, 2025
Browsershot Local File Inclusion
Moderate
CVE-2025-1026
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
wasmvm: Malicious smart contract can slow down block production
Moderate
GHSA-mx2j-7cmv-353c
was published
for
cosmwasm-vm
(Go)
Feb 4, 2025
wasmvm: Malicious smart contract can crash the chain
Moderate
GHSA-23qp-3c2m-xx6w
was published
for
github.com/CosmWasm/wasmvm
(Go)
Feb 4, 2025
Vitest browser mode serves arbitrary files
Moderate
CVE-2025-24963
was published
for
@vitest/browser
(npm)
Feb 4, 2025
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
Moderate
CVE-2025-23015
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
Moderate
CVE-2025-24860
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
Apache Cassandra: unrestricted deserialization of JMX authentication credentials
Moderate
CVE-2024-27137
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Feb 4, 2025
ZX Allows Environment Variable Injection for dotenv API
Moderate
CVE-2025-24959
was published
for
zx
(npm)
Feb 3, 2025
rust-openssl ssl::select_next_proto use after free
Moderate
CVE-2025-24898
was published
for
openssl
(Rust)
Feb 3, 2025
S3Proxy allows insecure path traversal in filesystem and filesystem-nio2 storage backends
Moderate
CVE-2025-24961
was published
for
org.gaul:s3proxy
(Maven)
Feb 3, 2025
ProTip!
Advisories are also available from the
GraphQL API