GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,042 advisories
Filter by severity
React Server Components are Vulnerable to RCE
Critical
GHSA-fmh4-wr37-44fp
was published
for
@vitejs/plugin-rsc
(npm)
Dec 3, 2025
React Server Components are Vulnerable to RCE
Critical
CVE-2025-55182
was published
for
react-server-dom-parcel
(npm)
Dec 3, 2025
Next.js is vulnerable to RCE in React flight protocol
Critical
CVE-2025-66478
was published
for
next
(npm)
Dec 3, 2025
MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL
Critical
CVE-2025-66401
was published
for
mcp-watch
(npm)
Dec 2, 2025
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
Critical
CVE-2025-62410
was published
for
happy-dom
(npm)
Oct 15, 2025
md-to-pdf vulnerable to arbitrary JavaScript code execution when parsing front matter
Critical
CVE-2025-65108
was published
for
md-to-pdf
(npm)
Nov 20, 2025
@hpke/core reuses AEAD nonces
Critical
CVE-2025-64767
was published
for
@hpke/core
(npm)
Nov 20, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
Flowise
(npm)
Oct 9, 2025
@react-native-community/cli has arbitrary OS command injection
Critical
CVE-2025-11953
was published
for
@react-native-community/cli
(npm)
Nov 3, 2025
Arbitrary Code Execution in underscore
Critical
CVE-2021-23358
was published
for
underscore
(npm)
May 6, 2021
sha.js is missing type checks leading to hash rewind and passing on crafted data
Critical
CVE-2025-9288
was published
for
sha.js
(npm)
Aug 21, 2025
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
Critical
CVE-2025-9287
was published
for
cipher-base
(npm)
Aug 21, 2025
form-data uses unsafe random function in form-data for choosing boundary
Critical
CVE-2025-7783
was published
for
form-data
(npm)
Jul 21, 2025
DOMPurify vulnerable to tampering by prototype polution
Critical
CVE-2024-48910
was published
for
dompurify
(npm)
Oct 31, 2024
Remote Code Execution Vulnerability in NPM mongo-express
Critical
CVE-2019-10758
was published
for
mongo-express
(npm)
Dec 30, 2019
FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
CVE-2025-57164
was published
for
flowise
(npm)
Sep 15, 2025
Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
GHSA-3g4j-r53p-22wx
was published
for
flowise
(npm)
Oct 17, 2025
•
withdrawn
Expo SDK has an OAuth vulnerability
Critical
CVE-2023-28131
was published
for
expo
(npm)
Apr 24, 2023
@nx/azure-cache Vulnerable to Build Cache Poisoning via Untrusted Pull Requests
Critical
CVE-2025-36852
was published
for
@nx/azure-cache
(npm)
Jun 10, 2025
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
CVE-2025-50538
was published
for
flowise
(npm)
Oct 3, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
Critical
CVE-2025-61928
was published
for
better-auth
(npm)
Oct 9, 2025
Authorization Bypass in Next.js Middleware
Critical
CVE-2025-29927
was published
for
next
(npm)
Mar 21, 2025
ProTip!
Advisories are also available from the
GraphQL API