GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            3,478 advisories
        Filter by severity
        
      
      
    
                    
                      DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
                    
                      
  Critical
                    
                
                      
                        CVE-2025-64095
                      
                      was published
                        for
                        
                          DNN.PLATFORM
                        
                        (NuGet)
                      Oct 29, 2025 
                    
                  
                    
                      Karmada Dashboard API Unauthorized Access Vulnerability 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62714
                      
                      was published
                        for
                        
                          github.com/karmada-io/dashboard
                        
                        (Go)
                      Oct 24, 2025 
                    
                  
                    
                      NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54469
                      
                      was published
                        for
                        
                          github.com/neuvector/neuvector
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      Cosmos EVM Vulnerability
                    
                      
  Critical
                    
                
                      
                        GHSA-8pfh-j44r-f654
                      
                      was published
                        for
                        
                          github.com/cosmos/evm
                        
                        (Go)
                      Oct 21, 2025 
                    
                  
                    
                      NetBird VPN does not remove the default password of an admin account
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10678
                      
                      was published
                        for
                        
                          github.com/netbirdio/netbird
                        
                        (Go)
                      Oct 20, 2025 
                    
                  
                    
                      MCMS vulnerable SQL injection via the content_title parameter
                    
                      
  Critical
                    
                
                      
                        CVE-2025-56316
                      
                      was published
                        for
                        
                          net.mingsoft:ms-mcms
                        
                        (Maven)
                      Oct 17, 2025 
                    
                  
                    
                      Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
                    
                      
  Critical
                    
                
                      
                        GHSA-3g4j-r53p-22wx
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Keras framework vulnerable to deserialization of untrusted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49655
                      
                      was published
                        for
                        
                          keras
                        
                        (pip)
                      Oct 17, 2025 
                    
                  
                    
                      pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62515
                      
                      was published
                        for
                        
                          pyquokka
                        
                        (pip)
                      Oct 17, 2025 
                    
                  
                    
                      bagisto has CSV Formula Injection in Create New Product
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62417
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      PrestaShop Checkout allows customer account takeover via email
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61922
                      
                      was published
                        for
                        
                          prestashop/ps_checkout
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      Apache ActiveMQ NMS AMQP Client has a Deserialization of Untrusted Data vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54539
                      
                      was published
                        for
                        
                          Apache.NMS.AMQP
                        
                        (NuGet)
                      Oct 16, 2025 
                    
                  
                    
                      happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62410
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
                    
                      Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55315
                      
                      was published
                        for
                        
                          Microsoft.AspNetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      Oct 14, 2025 
                    
                  
                    
                      Happy DOM: VM Context Escape can lead to Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61927
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 10, 2025 
                    
                  
                    
                      BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10283
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10284
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      Better Auth: Unauthenticated API key creation through api-key plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61928
                      
                      was published
                        for
                        
                          better-auth
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
                    
                      Flowise is vulnerable to arbitrary file write through its WriteFileTool 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61913
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
                    
                      scio is vunerable to  Remote Command Execution  through PyTorch
                    
                      
  Critical
                    
                
                      
                        GHSA-m9mp-6x32-5rhg
                      
                      was published
                        for
                        
                          scio-pypi
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      Melis Platform CMS Unauthenticated File Upload Leading to RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10353
                      
                      was published
                        for
                        
                          melisplatform/melis-cms-slider
                        
                        (Composer)
                      Oct 8, 2025 
                    
                  
                    
                      Melis Platform CMS Unauthenticated Admin Account Creation
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10352
                      
                      was published
                        for
                        
                          melisplatform/melis-core
                        
                        (Composer)
                      Oct 8, 2025 
                    
                  
                    
                      Melis Platform CMS SQL Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10351
                      
                      was published
                        for
                        
                          melisplatform/melis-cms
                        
                        (Composer)
                      Oct 8, 2025 
                    
                  
                    
                      Akka.Remote TLS did not properly implement certificate-based authentication
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61778
                      
                      was published
                        for
                        
                          Akka.Cluster
                        
                        (NuGet)
                      Oct 7, 2025 
                    
                  
                    
                      SillyTavern Web Interface Vulnerable DNS Rebinding
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59159
                      
                      was published
                        for
                        
                          sillytavern
                        
                        (npm)
                      Oct 6, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API