GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
26
Go
2,274
Maven
5,000+
npm
3,930
NuGet
706
pip
3,696
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,494 advisories
Filter by severity
October CMS Allows Unprotected SVG Rename in Media Manager
Low
CVE-2024-51991
was published
for
october/october
(Composer)
May 5, 2025
WSO2 API Manager XML External Entity (XXE) vulnerability
Critical
CVE-2025-2905
was published
for
org.wso2.am:am-distribution-parent
(Maven)
May 5, 2025
Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL
Critical
GHSA-f54f-hr32-586f
was published
for
browser-use
(pip)
May 3, 2025
•
withdrawn
Grokability Snipe-IT has incorrect authorization for accessing asset information
Moderate
CVE-2025-47226
was published
for
snipe/snipe-it
(Composer)
May 2, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization
Moderate
CVE-2025-3879
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
Moderate
CVE-2025-4210
was published
for
github.com/casdoor/casdoor
(Go)
May 2, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2025-4166
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
@cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
CVE-2025-4144
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
@cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
CVE-2025-4143
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
SQL injection in ADOdb PostgreSQL driver pg_insert_id() method
Critical
CVE-2025-46337
was published
for
adodb/adodb-php
(Composer)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
GHSA-7cp4-jw97-3rc2
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
GHSA-vh4h-fvqf-q9wv
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Panic in mp3-metadata due to the lack of bounds checking
Moderate
GHSA-927q-g9w9-pm54
was published
for
mp3-metadata
(Rust)
Apr 30, 2025
Vite's server.fs.deny bypassed with /. for files under project root
Moderate
CVE-2025-46565
was published
for
vite
(npm)
Apr 30, 2025
Keycloak vulnerable to two factor authentication bypass
Moderate
CVE-2025-3910
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
Keycloak hostname verification
High
CVE-2025-3501
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 30, 2025
org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content
Critical
CVE-2025-46558
was published
for
org.xwiki.contrib.markdown:syntax-markdown-commonmark12
(Maven)
Apr 30, 2025
Any user with view access to the XWiki space can change the authenticator
High
CVE-2025-46557
was published
for
org.xwiki.platform:xwiki-platform-security-authentication-ui
(Maven)
Apr 30, 2025
XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
Moderate
CVE-2025-46554
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Apr 30, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-46331
was published
for
github.com/openfga/openfga
(Go)
Apr 30, 2025
Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin
High
CVE-2025-32777
was published
for
volcano.sh/volcano
(Go)
Apr 30, 2025
Homograph attack allows Unicode lookalike characters to bypass validation.
High
CVE-2025-27611
was published
for
base-x
(npm)
Apr 30, 2025
ProTip!
Advisories are also available from the
GraphQL API