GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,632 advisories
Filter by severity
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Low
CVE-2025-64345
was published
for
wasmtime
(Rust)
Nov 12, 2025
sudo-rs: Partial password reveal is possible after timeout
Low
CVE-2025-64170
was published
for
sudo-rs
(Rust)
Nov 12, 2025
changedetection.io: Stored XSS in Watch update via API
Low
CVE-2025-62780
was published
for
changedetection.io
(pip)
Nov 12, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Low
CVE-2025-64326
was published
for
weblate
(pip)
Nov 5, 2025
min-document vulnerable to prototype pollution
Low
CVE-2025-57352
was published
for
min-document
(npm)
Sep 24, 2025
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
Low
GHSA-w2jf-268q-mrvh
was published
for
github.com/opentofu/opentofu
(Go)
Nov 6, 2025
Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode
Low
GHSA-cf57-c578-7jvv
was published
for
github.com/TecharoHQ/anubis
(Go)
Oct 30, 2025
Apereo CAS code injection vulnerability
Low
CVE-2025-3984
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2025-61795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Low
CVE-2025-55754
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability
Low
CVE-2025-61581
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Oct 16, 2025
Django vulnerable to partial directory traversal via archives
Low
CVE-2025-59682
was published
for
django
(pip)
Oct 1, 2025
Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
Low
CVE-2025-53678
was published
for
io.jenkins.plugins:user1st-utester
(Maven)
Jul 9, 2025
Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
Low
CVE-2025-53661
was published
for
io.jenkins.plugins:testsigma
(Maven)
Jul 9, 2025
Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project
Low
CVE-2024-20925
was published
for
org.openjfx:javafx-media
(Maven)
Feb 17, 2024
RDoc RCE vulnerability with .rdoc_options
Low
CVE-2024-27281
was published
for
rdoc
(RubyGems)
Mar 25, 2024
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Low
CVE-2024-30261
was published
for
undici
(npm)
Apr 4, 2024
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Low
CVE-2024-30260
was published
for
undici
(npm)
Apr 4, 2024
Kgateway transformation policy template can emit files from the container
Low
GHSA-5pmx-7r6r-wfqq
was published
for
github.com/kgateway-dev/kgateway/v2
(Go)
Nov 4, 2025
Elliptic allows BER-encoded signatures
Low
CVE-2024-42461
was published
for
elliptic
(npm)
Aug 2, 2024
Elliptic's ECDSA missing check for whether leading bit of r and s is zero
Low
CVE-2024-42460
was published
for
elliptic
(npm)
Aug 2, 2024
Elliptic's EDDSA missing signature length check
Low
CVE-2024-42459
was published
for
elliptic
(npm)
Aug 2, 2024
Protobuf Maven Plugin protocDigest is ignored when using protoc from PATH
Low
GHSA-j2pc-v64r-mv4f
was published
for
io.github.ascopes:protobuf-maven-plugin
(Maven)
Nov 4, 2025
ProTip!
Advisories are also available from the
GraphQL API