GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,203
Maven
5,000+
npm
3,857
NuGet
696
pip
3,639
Pub
12
RubyGems
912
Rust
913
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,908 advisories
Filter by severity
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
High
CVE-2025-30358
was published
for
mesop
(pip)
Mar 27, 2025
Synapse vulnerable to federation denial of service via malformed events
High
CVE-2025-30355
was published
for
matrix-synapse
(pip)
Mar 27, 2025
Pitchfork HTTP Request/Response Splitting vulnerability
Moderate
CVE-2025-30221
was published
for
pitchfork
(RubyGems)
Mar 27, 2025
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Moderate
CVE-2025-27793
was published
for
vega
(npm)
Mar 27, 2025
Apache Kylin Code Injection via JDBC Configuration Alteration
Low
CVE-2025-30067
was published
for
org.apache.kylin:kylin
(Maven)
Mar 27, 2025
Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
Low
CVE-2024-48944
was published
for
org.apache.kylin:kylin-common-server
(Maven)
Mar 27, 2025
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter
Moderate
CVE-2025-26619
was published
for
vega
(npm)
Mar 27, 2025
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
Moderate
GHSA-9cc5-2pq7-hfj8
was published
for
xmas-elf
(Rust)
Mar 26, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
Directus `search` query parameter allows enumeration of non permitted fields
Moderate
CVE-2025-30352
was published
for
directus
(npm)
Mar 26, 2025
Suspended Directus user can continue to use session token to access API
Low
CVE-2025-30351
was published
for
directus
(npm)
Mar 26, 2025
Directus's S3 assets become unavailable after a burst of HEAD requests
Moderate
CVE-2025-30350
was published
for
@directus/storage-driver-s3
(npm)
Mar 26, 2025
Directus's S3 assets become unavailable after a burst of malformed transformations
Moderate
CVE-2025-30225
was published
for
@directus/storage-driver-s3
(npm)
Mar 26, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30217
was published
for
frappe
(pip)
Mar 26, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
Moderate
CVE-2024-12369
was published
for
org.wildfly.security:wildfly-elytron
(Maven)
Mar 25, 2025
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
Frappe vulnerable to information disclosure leading to account takeover
High
CVE-2025-30214
was published
for
frappe
(pip)
Mar 25, 2025
Frappe has Possibility of Remote Code Execution due to improper validation
Moderate
CVE-2025-30213
was published
for
frappe
(pip)
Mar 25, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30212
was published
for
frappe
(pip)
Mar 25, 2025
Vite bypasses server.fs.deny when using ?raw??
Moderate
CVE-2025-30208
was published
for
vite
(npm)
Mar 25, 2025
Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache
Moderate
CVE-2025-2559
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 25, 2025
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
High
CVE-2025-1097
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ProTip!
Advisories are also available from the
GraphQL API