GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,820 advisories
Filter by severity
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
Low
GHSA-rcmh-qjqh-p98v
was published
for
nodemailer
(npm)
Dec 1, 2025
Spotipy has a XSS vulnerability in its OAuth callback server
Low
CVE-2025-66040
was published
for
spotipy
(pip)
Dec 1, 2025
Withdrawn Advisory: express improperly controls modification of query properties
Low
CVE-2024-51999
was published
for
express
(npm)
Dec 1, 2025
•
withdrawn
When loading a plist file, the plistlib module reads data in size specified by the file itself,...
Low
Unreviewed
CVE-2025-13837
was published
Dec 1, 2025
Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information...
Low
Unreviewed
CVE-2025-13129
was published
Dec 1, 2025
NutzBoot vulnerable to information disclosure
Low
CVE-2025-13804
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
NutzBoot vulnerable to deserialization
Low
CVE-2025-13805
was published
for
org.nutz:nutzboot-parent
(Maven)
Dec 1, 2025
A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by...
Low
Unreviewed
CVE-2025-6666
was published
Nov 29, 2025
In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of...
Low
Unreviewed
CVE-2025-66382
was published
Nov 28, 2025
Mustangproject allows exfiltrating files via XXE attacks
Low
CVE-2025-66372
was published
for
org.mustangproject:library
(Maven)
Nov 28, 2025
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server:...
Low
Unreviewed
CVE-2025-13758
was published
Nov 27, 2025
Emails sent by pretix can utilize placeholders that will be filled with customer data. For...
Low
Unreviewed
CVE-2025-13742
was published
Nov 27, 2025
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
Low
GHSA-wmjr-v86c-m9jj
was published
for
better-auth
(npm)
Nov 26, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
Low
CVE-2025-65681
was published
for
tutor
(pip)
Nov 26, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18...
Low
Unreviewed
CVE-2025-13611
was published
Nov 26, 2025
In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets...
Low
Unreviewed
CVE-2025-20373
was published
Nov 26, 2025
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in...
Low
Unreviewed
CVE-2025-2486
was published
Nov 26, 2025
In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the...
Low
Unreviewed
CVE-2025-55174
was published
Nov 26, 2025
Contao is vulnerable to cross-site scripting in templates
Low
CVE-2025-65961
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
Low
CVE-2025-65942
was published
for
github.com/VictoriaMetrics/VictoriaMetrics
(Go)
Nov 25, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a...
Low
Unreviewed
CVE-2025-33198
was published
Nov 25, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a...
Low
Unreviewed
CVE-2025-33200
was published
Nov 25, 2025
NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause...
Low
Unreviewed
CVE-2025-33199
was published
Nov 25, 2025
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0...
Low
Unreviewed
CVE-2025-36134
was published
Nov 25, 2025
A user with access to the cluster with a limited set of privilege actions may be able to...
Low
Unreviewed
CVE-2025-13643
was published
Nov 25, 2025
ProTip!
Advisories are also available from the
GraphQL API