GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,801
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,010
NuGet
720
pip
3,810
Pub
12
RubyGems
930
Rust
986
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,161 advisories
Filter by severity
DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
Moderate
CVE-2025-53622
was published
for
org.dspace:dspace-api
(Maven)
Jul 15, 2025
DSpace is vulnerable to XML External Entity injection during archive imports
Moderate
CVE-2025-53621
was published
for
org.dspace:dspace-api
(Maven)
Jul 15, 2025
GitHub Kanban MCP Server vulnerable to Command Injection
High
CVE-2025-53818
was published
for
@sunwood-ai-labs/github-kanban-mcp-server
(npm)
Jul 15, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
Moderate
CVE-2025-53889
was published
for
directus
(npm)
Jul 15, 2025
Measured is vulnerable to Path Traversal attacks during class initialization
Moderate
GHSA-29g5-m8v7-v564
was published
for
measured
(RubyGems)
Jul 15, 2025
Directus' exact version number is exposed by the OpenAPI Spec
Moderate
CVE-2025-53887
was published
for
directus
(npm)
Jul 15, 2025
Directus tokens are not redacted in flow logs, exposing session credentials to all admin
Moderate
CVE-2025-53886
was published
for
directus
(npm)
Jul 15, 2025
Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged
Moderate
CVE-2025-53885
was published
for
directus
(npm)
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Moderate
CVE-2025-24294
was published
for
resolv
(RubyGems)
Jul 15, 2025
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Critical
CVE-2025-53836
was published
for
org.xwiki.rendering:xwiki-rendering-transformation-macro
(Maven)
Jul 14, 2025
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
Critical
CVE-2025-53835
was published
for
org.xwiki.rendering:xwiki-rendering-syntax-xhtml
(Maven)
Jul 14, 2025
LaRecipe is vulnerable to Server-Side Template Injection attacks
Critical
CVE-2025-53833
was published
for
binarytorch/larecipe
(Composer)
Jul 14, 2025
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
Low
CVE-2025-53643
was published
for
aiohttp
(pip)
Jul 14, 2025
Indico vulnerability allows attackers to bulk dump user details
Moderate
CVE-2025-53640
was published
for
indico
(pip)
Jul 14, 2025
Job Iteration API is vulnerable to OS Command Injection attack through its CsvEnumerator class
High
CVE-2025-53623
was published
for
job-iteration
(RubyGems)
Jul 14, 2025
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
High
CVE-2025-53689
was published
for
org.apache.jackrabbit:jackrabbit-core
(Maven)
Jul 14, 2025
py-libp2p is vulnerable to DoS attacks through use of large RSA keys
Moderate
CVE-2025-29606
was published
for
libp2p
(pip)
Jul 14, 2025
Roundup is vulnerable to XSS through interactions between URLs and issue tracker templates
Moderate
CVE-2025-53865
was published
for
roundup
(pip)
Jul 13, 2025
Apache Zeppelin exposes server resources to unauthenticated attackers
High
CVE-2024-41169
was published
for
org.apache.zeppelin:zeppelin-interpreter
(Maven)
Jul 12, 2025
static-alloc vulnerability leads to uninitialized read after allocating MemBump
Low
GHSA-xrrq-rrgq-h89w
was published
for
static-alloc
(Rust)
Jul 11, 2025
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
High
CVE-2025-30402
was published
for
executorch
(pip)
Jul 11, 2025
Better Call routing bug can lead to Cache Deception
Moderate
GHSA-hq75-xg7r-rx6c
was published
for
better-call
(npm)
Jul 11, 2025
phpThumb is vulnerable to Command Injection through its gif_outputAsJpeg function
Moderate
CVE-2025-52994
was published
for
james-heinrich/phpthumb
(Composer)
Jul 11, 2025
Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
Moderate
CVE-2025-48924
was published
for
commons-lang:commons-lang
(Maven)
Jul 11, 2025
ProTip!
Advisories are also available from the
GraphQL API