GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,554
Maven
5,000+
npm
4,225
NuGet
746
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,589 advisories
Filter by severity
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
CVE-2025-61921
was published
for
sinatra
(RubyGems)
Oct 10, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Fiora chat user avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56514
was published
for
fiora
(npm)
Oct 1, 2025
Deno's --deny-write check does not prevent permission bypass
Low
CVE-2025-61785
was published
for
deno
(Rust)
Oct 7, 2025
DataChain Vulnerable to Deserialization of Untrusted Data from Environment Variables
Low
CVE-2025-61677
was published
for
datachain
(pip)
Oct 2, 2025
Claude Code permission deny bypass through symlink
Low
CVE-2025-59829
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low
CVE-2025-11570
was published
for
drupal-pattern-lab/unified-twig-extensions
(Composer)
Oct 10, 2025
MCPHub's ServerController is vulnerable to Command Injection
Low
CVE-2025-11285
was published
for
@samanhappy/mcphub
(npm)
Oct 5, 2025
WSO2's Input Validation Management Service contains Observable Discrepancy when Multi-Attribute Login is enabled
Low
CVE-2025-1396
was published
for
org.wso2.carbon.identity.framework:org.wso2.carbon.identity.input.validation.mgt
(Maven)
Sep 26, 2025
Deno's --deny-read check does not prevent permission bypass
Low
CVE-2025-61786
was published
for
deno
(Rust)
Oct 8, 2025
rollbar vulnerable to prototype pollution
Low
CVE-2025-57325
was published
for
rollbar
(npm)
Sep 24, 2025
NovoSGA: Manipulation of User Creation Page can lead to weak password requirements
Low
CVE-2025-11322
was published
for
novosga/novosga
(Composer)
Oct 6, 2025
wrflib has a soundness issue and is unmaintained
Low
GHSA-466c-pfvv-v83g
was published
for
wrflib
(Rust)
Oct 3, 2025
Django vulnerable to partial directory traversal via archives
Low
CVE-2025-59682
was published
for
django
(pip)
Oct 1, 2025
auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
Low
CVE-2025-58769
was published
for
auth0/auth0-php
(Composer)
Oct 1, 2025
Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-7jp2-5h22-m432
was published
for
auth0/symfony
(Composer)
Oct 1, 2025
Auth0 Wordpress plugin Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-w22c-pw5m-482x
was published
for
auth0/wordpress
(Composer)
Oct 1, 2025
laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-hjfh-5jmm-xr24
was published
for
auth0/login
(Composer)
Oct 1, 2025
Fiora chat group avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56515
was published
for
fiora
(npm)
Oct 1, 2025
vet MCP Server SSE Transport DNS Rebinding Vulnerability
Low
CVE-2025-59163
was published
for
github.com/safedep/vet
(Go)
Sep 29, 2025
min-document vulnerable to prototype pollution
Low
CVE-2025-57352
was published
for
min-document
(npm)
Sep 24, 2025
fast-redact vulnerable to prototype pollution
Low
CVE-2025-57319
was published
for
fast-redact
(npm)
Sep 24, 2025
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Low
CVE-2025-59842
was published
for
jupyterlab
(pip)
Sep 26, 2025
Next.js Race Condition to Cache Poisoning
Low
CVE-2025-32421
was published
for
next
(npm)
May 15, 2025
ProTip!
Advisories are also available from the
GraphQL API