GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,076 advisories
Filter by severity
Static Web Server vulnerable to a symbolic link path traversal
Moderate
CVE-2025-67487
was published
for
static-web-server
(Rust)
Dec 8, 2025
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
Moderate
CVE-2025-66470
was published
for
nicegui
(pip)
Dec 8, 2025
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
Moderate
CVE-2025-66469
was published
for
nicegui
(pip)
Dec 8, 2025
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Moderate
CVE-2025-66578
was published
for
robrichards/xmlseclibs
(Composer)
Dec 8, 2025
1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers
Moderate
CVE-2025-66508
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Moderate
CVE-2025-66491
was published
for
github.com/traefik/traefik/v3
(Go)
Dec 8, 2025
Path Normalization Bypass in Traefik Router + Middleware Rules
Moderate
CVE-2025-66490
was published
for
github.com/traefik/traefik
(Go)
Dec 8, 2025
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Moderate
CVE-2025-66202
was published
for
astro
(npm)
Dec 8, 2025
nitro-tpm-pcr-compute may allow kernel command line modification by an account operator
Moderate
GHSA-xrv8-2pf5-f3q7
was published
for
nitro-tpm-pcr-compute
(Rust)
Dec 5, 2025
Envoy's TLS certificate matcher for `match_typed_subject_alt_names` may incorrectly treat certificates containing an embedded null byte
Moderate
CVE-2025-66220
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Envoy crashes when JWT authentication is configured with the remote JWKS fetching
Moderate
CVE-2025-64527
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
ComposioHQ has a directory traversal vulnerability
Moderate
CVE-2025-56427
was published
for
composio
(pip)
Dec 4, 2025
Central Dogma's Login Function Has an Open Redirect Vulnerability
Moderate
CVE-2025-11222
was published
for
com.linecorp.centraldogma:centraldogma-server-auth-shiro
(Maven)
Dec 4, 2025
Ansible Community General Collection is vulnerable to exposure of sensitive information
Moderate
CVE-2025-14010
was published
for
ansible
(pip)
Dec 4, 2025
mcp-server-kubernetes has potential security issue in exec_in_pod tool
Moderate
CVE-2025-66404
was published
for
mcp-server-kubernetes
(npm)
Dec 3, 2025
step-ca Has Improper Authorization Check for SSH Certificate Revocation
Moderate
CVE-2025-66406
was published
for
github.com/smallstep/certificates
(Go)
Dec 3, 2025
ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family
Moderate
CVE-2025-65955
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 3, 2025
BlazeMeter Jenkins Plugin is Missing Authorization for Available Resources
Moderate
CVE-2025-13472
was published
for
com.blazemeter.plugins:BlazeMeterJenkinsPlugin
(Maven)
Dec 3, 2025
FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management
Moderate
CVE-2025-65657
was published
for
feehi/cms
(Composer)
Dec 2, 2025
Apptainer ineffectively applies selinux and apparmor --security options
Moderate
CVE-2025-65105
was published
for
github.com/apptainer/apptainer
(Go)
Dec 2, 2025
Singluarity ineffectively applies selinux / apparmor LSM process labels
Moderate
CVE-2025-64750
was published
for
github.com/sylabs/singularity/v4
(Go)
Dec 2, 2025
Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor
Moderate
CVE-2025-65186
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
Django is vulnerable to DoS via XML serializer text extraction
Moderate
CVE-2025-64460
was published
for
Django
(pip)
Dec 2, 2025
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
Moderate
CVE-2025-66454
was published
for
arcade-mcp-server
(pip)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API