GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
102 advisories
Filter by severity
Visual Studio Code Go extension has unexpected untrusted code execution
Moderate
CVE-2025-68120
was published
for
github.com/golang/vscode-go
(Go)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Moderate
GHSA-6556-fwc2-fg2p
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
Moderate
GHSA-cffc-mxrf-mhh4
was published
for
picklescan
(pip)
Dec 29, 2025
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Moderate
CVE-2025-65026
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
SimStudioAI: A function in route.ts is vulnerable to Code Injection
Moderate
CVE-2025-10097
was published
for
simstudio
(npm)
Sep 8, 2025
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Moderate
CVE-2025-35036
was published
for
org.hibernate.validator:hibernate-validator
(Maven)
Jun 3, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
lychee link checking action affected by arbitrary code injection in composite action
Moderate
CVE-2024-48908
was published
for
lycheeverse/lychee-action
(GitHub Actions)
Aug 28, 2025
Craft CMS has a theoretical bypass for CVE-2025-23209
Moderate
CVE-2025-54417
was published
for
craftcms/cms
(Composer)
Aug 8, 2025
Pyload log Injection via API /json/add_package in add_name parameter
Moderate
GHSA-3wwm-hjv7-23r3
was published
for
pyload-ng
(pip)
Jul 30, 2025
HashiCorp Vagrant has code injection vulnerability through default synced folders
Moderate
CVE-2025-34075
was published
for
vagrant
(RubyGems)
Jul 2, 2025
Stage.js DOM Clobbering vulnerabilty
Moderate
CVE-2024-53386
was published
for
stage-js
(npm)
Mar 3, 2025
PrismJS DOM Clobbering vulnerability
Moderate
CVE-2024-53382
was published
for
prismjs
(npm)
Mar 3, 2025
Remote code execution via the `pretty` option.
Moderate
CVE-2021-21353
was published
for
pug
(npm)
Mar 3, 2021
OZI-Project/ozi-publish Code Injection vulnerability
Moderate
CVE-2025-47271
was published
for
OZI-Project/publish
(GitHub Actions)
May 12, 2025
Froxlor vulnerable to Code Injection
Moderate
CVE-2022-3721
was published
for
froxlor/froxlor
(Composer)
Nov 4, 2022
Flair allows arbitrary code execution
Moderate
CVE-2024-10073
was published
for
flair
(pip)
Oct 17, 2024
Pug allows JavaScript code execution if an application accepts untrusted input
Moderate
CVE-2024-36361
was published
for
pug
(npm)
May 24, 2024
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
nest allows a remote attacker to execute arbitrary code via the Content-Type header
Moderate
CVE-2024-29409
was published
for
@nestjs/common
(npm)
Mar 14, 2025
RaspAP Vulnerable to Code Injection via an Unknown Process in File `includes/provider.php`
Moderate
CVE-2024-2497
was published
for
billz/raspap-webgui
(Composer)
Mar 15, 2024
Dolibarr ERP CRM Code Injection vulnerability during installation
Moderate
CVE-2024-29477
was published
for
dolibarr/dolibarr
(Composer)
Apr 3, 2024
ProTip!
Advisories are also available from the
GraphQL API