GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
5,030 advisories
Filter by severity
Frappe has Possibility of Remote Code Execution due to improper validation
Moderate
CVE-2025-30213
was published
for
frappe
(pip)
Mar 25, 2025
ingress-nginx controller - auth secret file path traversal vulnerability
Moderate
CVE-2025-24513
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
API Platform Core does not call GraphQl securityAfterResolver
Moderate
CVE-2025-23204
was published
for
api-platform/core
(Composer)
Mar 24, 2025
yiisoft Yii2 Deserialization of Untrusted Data
Moderate
CVE-2025-2689
was published
for
yiisoft/yii2-dev
(Composer)
Mar 24, 2025
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This...
Moderate
Unreviewed
CVE-2025-2690
was published
Mar 24, 2025
aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
Moderate
CVE-2025-2622
was published
for
com.aizuda:snail-job
(Maven)
Mar 22, 2025
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
Moderate
Unreviewed
CVE-2024-13666
was published
Mar 22, 2025
A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection....
Moderate
Unreviewed
CVE-2024-8251
was published
Mar 20, 2025
A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an...
Moderate
Unreviewed
CVE-2024-12387
was published
Mar 20, 2025
gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion...
Moderate
Unreviewed
CVE-2024-10707
was published
Mar 20, 2025
A vulnerability has been found in viames Pair Framework up to 1.9.11 and classified as critical....
Moderate
Unreviewed
CVE-2025-2376
was published
Mar 17, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
Moderate
CVE-2024-9042
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access
Moderate
CVE-2025-1767
was published
for
k8s.io/kubernetes
(Go)
Mar 13, 2025
HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
Moderate
CVE-2025-22870
was published
for
golang.org/x/net
(Go)
Mar 12, 2025
Improper Input Validation vulnerability in ZTE GoldenDB allows Input Data Manipulation.This issue...
Moderate
Unreviewed
CVE-2025-26702
was published
Mar 11, 2025
Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality
Moderate
CVE-2025-0660
was published
for
concrete5/concrete5
(Composer)
Mar 10, 2025
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60...
Moderate
Unreviewed
CVE-2025-27253
was published
Mar 10, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
GHSA-2gh3-rmm4-6rq5
was published
for
protobuf
(Rust)
Mar 7, 2025
A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue...
Moderate
Unreviewed
CVE-2025-2043
was published
Mar 7, 2025
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache...
Moderate
Unreviewed
CVE-2024-38311
was published
Mar 6, 2025
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized access...
Moderate
Unreviewed
CVE-2025-0958
was published
Mar 4, 2025
The user input was not sanitized on Reporting Hierarchy Management page of Foreseer Reporting...
Moderate
Unreviewed
CVE-2025-22491
was published
Feb 28, 2025
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient...
Moderate
Unreviewed
CVE-2025-0764
was published
Feb 28, 2025
A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this...
Moderate
Unreviewed
CVE-2025-1741
was published
Feb 27, 2025
A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0....
Moderate
Unreviewed
CVE-2025-1556
was published
Feb 22, 2025
ProTip!
Advisories are also available from the
GraphQL API