GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,486
Maven
5,000+
npm
4,104
NuGet
735
pip
3,918
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
305 advisories
Filter by severity
@backstage/backend-app-api leaks GitLab access tokens
High
CVE-2023-6944
was published
for
@backstage/backend-app-api
(npm)
Jan 4, 2024
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High
CVE-2025-6984
was published
for
langchain-community
(pip)
Sep 4, 2025
@musistudio/claude-code-router has improper CORS configuration
High
CVE-2025-57755
was published
for
@musistudio/claude-code-router
(npm)
Aug 21, 2025
The AuthKit Remix Library renders sensitive auth data in HTML
High
CVE-2025-55009
was published
for
@workos-inc/authkit-remix
(npm)
Aug 8, 2025
The AuthKit React Router Library rendered sensitive auth data in HTML
High
CVE-2025-55008
was published
for
@workos-inc/authkit-react-router
(npm)
Aug 8, 2025
GitProxy Hidden Commits Injection
High
CVE-2025-54586
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
Janssen Config API returns results without scope verification
High
CVE-2025-53003
was published
for
io.jans:jans-config-api-server
(Maven)
Jun 30, 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
High
CVE-2025-49653
was published
for
backend.ai
(pip)
Jun 9, 2025
XML External Entity Injection in XStream
High
CVE-2016-3674
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jun 30, 2020
Moodle Authenticated LFI risk in some misconfigured shared hosting environments
High
CVE-2024-34005
was published
for
moodle/moodle
(Composer)
May 31, 2024
OXID eShop May Display User Information
High
CVE-2024-56526
was published
for
oxid-esales/oxideshop-ce
(Composer)
May 13, 2025
Moodle allows unauthenticated REST API user data exposure
High
CVE-2025-32044
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
"Newsletter subscriber management" (fp_newsletter) TYPO3 extension leaks subscriber data
High
CVE-2022-47410
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
"Newsletter subscriber management" (fp_newsletter) TYPO3 extension leaks subscriber data
High
CVE-2022-47411
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
The Direct Mail (direct_mail) TYPO3 extension improperly discloses sensitive information
High
CVE-2013-7400
was published
for
directmailteam/direct-mail
(Composer)
May 13, 2022
Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)
High
CVE-2024-46987
was published
for
camaleon_cms
(RubyGems)
Sep 18, 2024
Withdrawn Advisory: Cluster Monitoring Operator contains a credentials leak
High
CVE-2024-1139
was published
for
github.com/openshift/cluster-monitoring-operator
(Go)
Apr 25, 2024
•
withdrawn
phpMyAdmin vulnerable to Cross-Site Request Forgery
High
CVE-2016-5739
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
WildFly has incomplete blacklist vulnerability
High
CVE-2016-0793
was published
for
org.wildfly:wildfly-parent
(Maven)
May 14, 2022
github.com/rancher/steve's users can issue watch commands for arbitrary resources
High
CVE-2024-52280
was published
for
github.com/rancher/steve
(Go)
Nov 20, 2024
TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`
High
CVE-2005-4875
was published
for
typo3/cms
(Composer)
May 1, 2022
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
Information disclosure issue in Active Resource
High
CVE-2020-8151
was published
for
activeresource
(RubyGems)
May 21, 2020
Frappe vulnerable to information disclosure leading to account takeover
High
CVE-2025-30214
was published
for
frappe
(pip)
Mar 25, 2025
ProTip!
Advisories are also available from the
GraphQL API