GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,891
Erlang
37
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,221
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,459 advisories
Filter by severity
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical
CVE-2025-10283
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical
CVE-2025-10284
was published
for
bbot
(pip)
Oct 9, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
Critical
GHSA-99h5-pjcv-gr6v
was published
for
better-auth
(npm)
Oct 9, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
flowise
(npm)
Oct 9, 2025
scio is vunerable to Remote Command Execution through PyTorch
Critical
GHSA-m9mp-6x32-5rhg
was published
for
scio-pypi
(pip)
Oct 9, 2025
Melis Platform CMS Unauthenticated Admin Account Creation
Critical
CVE-2025-10352
was published
for
melisplatform/melis-core
(Composer)
Oct 8, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
CVE-2025-10353
was published
for
melisplatform/melis-cms-slider
(Composer)
Oct 8, 2025
Melis Platform CMS SQL Injection
Critical
CVE-2025-10351
was published
for
melisplatform/melis-cms
(Composer)
Oct 8, 2025
Akka.Remote TLS did not properly implement certificate-based authentication
Critical
CVE-2025-61778
was published
for
Akka.Cluster
(NuGet)
Oct 7, 2025
SillyTavern Web Interface Vulnerable DNS Rebinding
Critical
CVE-2025-59159
was published
for
sillytavern
(npm)
Oct 6, 2025
XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
Critical
CVE-2025-52472
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Oct 6, 2025
XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
Critical
CVE-2025-49594
was published
for
org.xwiki.contrib.oidc:oidc-authenticator
(Maven)
Oct 6, 2025
Flowise vulnerable to RCE via Dynamic function constructor injection
Critical
CVE-2025-55346
was published
for
flowise
(npm)
Oct 6, 2025
Flowise vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
GHSA-964p-j4gg-mhwc
was published
for
flowise
(npm)
Oct 3, 2025
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
Critical
CVE-2025-61588
was published
for
risc0-aggregation
(Rust)
Oct 1, 2025
Apache Pyfory python is vulnerable to deserialization of untrusted data
Critical
CVE-2025-61622
was published
for
pyfory
(pip)
Oct 1, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
j178/prek-action vulnerable to arbitrary code injection in composite action
Critical
GHSA-pwf7-47c3-mfhx
was published
for
j178/prek-action
(GitHub Actions)
Sep 29, 2025
get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass
Critical
CVE-2025-59936
was published
for
get-jwks
(npm)
Sep 26, 2025
Gardener provider extensions vulnerable to code injection when Terraform is used for infrastructure provisioning
Critical
CVE-2025-59823
was published
for
github.com/gardener/gardener-extension-provider-aws
(Go)
Sep 25, 2025
cors-anywhere vulnerable to server-side request forgery
Critical
CVE-2020-36851
was published
for
cors-anywhere
(npm)
Sep 25, 2025
Duplicate Advisory: Malicious versions of Nx were published
Critical
GHSA-8mjq-32x3-22qf
was published
for
nx
(npm)
Sep 25, 2025
•
withdrawn
Command Injection in adb-mcp MCP Server
Critical
CVE-2025-59834
was published
for
adb-mcp
(npm)
Sep 24, 2025
Apache IoTDB: Deserialization of untrusted Data
Critical
CVE-2025-48459
was published
for
org.apache.iotdb:iotdb-confignode
(Maven)
Sep 24, 2025
ProTip!
Advisories are also available from the
GraphQL API