GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,615 advisories
Filter by severity
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client
High
CVE-2025-66035
was published
for
@angular/common
(npm)
Nov 26, 2025
node-forge has ASN.1 Unbounded Recursion
High
CVE-2025-66031
was published
for
node-forge
(npm)
Nov 26, 2025
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
High
CVE-2025-12816
was published
for
node-forge
(npm)
Nov 26, 2025
Valibot has a ReDoS vulnerability in `EMOJI_REGEX`
High
CVE-2025-66020
was published
for
valibot
(npm)
Nov 26, 2025
OneUptime Unauthorized User Creation via API
High
CVE-2025-65966
was published
for
@oneuptime/common
(npm)
Nov 26, 2025
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
High
CVE-2025-66021
was published
for
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
(Maven)
Nov 25, 2025
Better Auth Passkey Plugin allows passkey deletion through IDOR
High
GHSA-4vcf-q4xf-f48m
was published
for
@better-auth/passkey
(npm)
Nov 25, 2025
OpenSearch is vulnerable to DoS via complex query_string inputs
High
CVE-2025-9624
was published
for
org.opensearch:opensearch-common
(Maven)
Nov 25, 2025
cggmp24 and cggmp21 are vulnerable to signature forgery through altered presignatures
High
CVE-2025-66017
was published
for
cggmp21
(Rust)
Nov 25, 2025
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
High
CVE-2025-62703
was published
for
fugue
(pip)
Nov 25, 2025
GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
High
CVE-2025-58360
was published
for
org.geoserver.web:gs-web-app
(Maven)
Nov 25, 2025
REDAXO CMS is vulnerable to RCE attack through its template management component
High
CVE-2025-64050
was published
for
redaxo/source
(Composer)
Nov 25, 2025
Grype has a credential disclosure vulnerability in its JSON output
High
CVE-2025-65965
was published
for
github.com/anchore/grype
(Go)
Nov 25, 2025
Babylon's malformed vote extensions are not rejected
High
GHSA-2fcv-qww3-9v6h
was published
for
github.com/babylonlabs-io/babylon/v4
(Go)
Nov 24, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
High
CVE-2025-64761
was published
for
github.com/openbao/openbao
(Go)
Nov 24, 2025
new-api is vulnerable to SSRF Bypass
High
CVE-2025-62155
was published
for
github.com/QuantumNous/new-api
(Go)
Nov 24, 2025
Keylime allows users to register new agents by recycling existing UUIDs when using different TPM devices
High
CVE-2025-13609
was published
for
keylime
(pip)
Nov 24, 2025
NSSF panic due to nil pointer dereference when expiry field is omitted in NSSAIAvailability POST
High
CVE-2025-60638
was published
for
github.com/free5gc/nssf
(Go)
Nov 24, 2025
Apache Syncope's AES encryption stores hard-coded passwords in internal database
High
CVE-2025-65998
was published
for
org.apache.syncope:syncope-core
(Maven)
Nov 24, 2025
thread-amount Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
High
CVE-2025-65947
was published
for
thread-amount
(Rust)
Nov 21, 2025
Vault’s Terraform Provider incorrectly set default deny_null_bind parameter for LDAP auth method to false by default
High
CVE-2025-13357
was published
for
github.com/hashicorp/terraform-provider-vault
(Go)
Nov 21, 2025
Minder does not sandbox http.send in Rego programs
High
GHSA-6xvf-4vh9-mw47
was published
for
github.com/mindersec/minder
(Go)
Nov 20, 2025
authkit-nextjs may let session cookies be cached in CDNs
High
CVE-2025-64762
was published
for
@workos-inc/authkit-nextjs
(npm)
Nov 20, 2025
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
High
CVE-2025-64755
was published
for
@anthropic-ai/claude-code
(npm)
Nov 20, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
High
CVE-2025-62372
was published
for
vllm
(pip)
Nov 20, 2025
ProTip!
Advisories are also available from the
GraphQL API