GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
9,192 advisories
Filter by severity
REXML denial of service vulnerability
Moderate
CVE-2024-39908
was published
for
rexml
(RubyGems)
Jul 16, 2024
Ansible-core information disclosure flaw
Moderate
CVE-2024-0690
was published
for
ansible-core
(pip)
Feb 6, 2024
KaTeX \htmlData does not validate attribute names
Moderate
CVE-2025-23207
was published
for
katex
(npm)
Jan 17, 2025
Flarum's logout Route allows open redirects
Moderate
CVE-2024-21641
was published
for
flarum/core
(Composer)
Jan 5, 2024
Missing Authorization in Jenkins Blue Ocean Plugin
Moderate
CVE-2017-1000105
was published
for
io.jenkins.blueocean:blueocean
(Maven)
May 13, 2022
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Moderate
CVE-2022-36109
was published
for
github.com/docker/docker
(Go)
Sep 16, 2022
Librenms has a reflected XSS on error alert
Moderate
CVE-2025-23201
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Misc Section Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23200
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23198
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Ports Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23199
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability
Moderate
CVE-2024-56144
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost Incorrect Type Conversion or Cast
Moderate
CVE-2025-21088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Matrix Media Repo (MMR) allows untrusted file formats can be thumbnailed, invoking potentially further untrusted decoders
Moderate
CVE-2024-56515
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows a denial of service through memory exhaustion
Moderate
CVE-2024-52791
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation
Moderate
CVE-2024-52602
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation
Moderate
CVE-2024-52594
was published
for
github.com/matrix-org/gomatrixserverlib
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows denial of service/high operating costs through unauthenticated downloads
Moderate
CVE-2024-36403
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
parse-uri Regular expression Denial of Service (ReDoS)
Moderate
CVE-2024-36751
was published
for
parse-uri
(npm)
Jan 16, 2025
matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content
Moderate
CVE-2024-36402
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20086
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost webapp crash via a crafted post
Moderate
CVE-2025-20621
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 16, 2025
http-swagger XSS via PUT requests
Moderate
CVE-2024-25712
was published
for
github.com/swaggo/http-swagger
(Go)
Feb 29, 2024
ProTip!
Advisories are also available from the
GraphQL API