GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
26
Go
2,274
Maven
5,000+
npm
3,930
NuGet
706
pip
3,696
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,930 advisories
Filter by severity
code-server's session cookie can be extracted by having user visit specially crafted proxy URL
High
CVE-2025-47269
was published
for
code-server
(npm)
May 9, 2025
Trix vulnerable to Cross-site Scripting on copy & paste
Low
CVE-2025-46812
was published
for
trix
(npm)
May 8, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Attribute Smuggling
High
CVE-2025-46573
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Signature Wrapping
Critical
CVE-2025-46572
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
@misskey-dev/summaly allows IP Filter Bypass via Redirect
Moderate
GHSA-jqx4-9gpq-rppm
was published
for
@misskey-dev/summaly
(npm)
May 6, 2025
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Low
CVE-2025-46720
was published
for
@keystone-6/core
(npm)
May 5, 2025
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
@cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
CVE-2025-4144
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
@cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
CVE-2025-4143
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
Duplicate Advisory: @cloudflare/workers-oauth-provider missing validation of redirect_uri on authorize endpoint
Moderate
GHSA-7cp4-jw97-3rc2
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Duplicate Advisory: @cloudflare/workers-oauth-provider PKCE bypass via downgrade attack
Moderate
GHSA-vh4h-fvqf-q9wv
was published
for
@cloudflare/workers-oauth-provider
(npm)
May 1, 2025
•
withdrawn
Vite's server.fs.deny bypassed with /. for files under project root
Moderate
CVE-2025-46565
was published
for
vite
(npm)
Apr 30, 2025
Homograph attack allows Unicode lookalike characters to bypass validation.
High
CVE-2025-27611
was published
for
base-x
(npm)
Apr 30, 2025
Auth0 NextJS SDK v4 Missing Session Invalidation
Moderate
CVE-2025-46344
was published
for
@auth0/nextjs-auth0
(npm)
Apr 29, 2025
AngularJS improperly sanitizes SVG elements
Low
CVE-2025-0716
was published
for
angular
(npm)
Apr 29, 2025
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Moderate
GHSA-wfm2-rq5g-f8v5
was published
for
@account-kit/smart-contracts
(npm)
Apr 29, 2025
n8n Vulnerable to Stored XSS through Attachments View Endpoint
Moderate
CVE-2025-46343
was published
for
n8n
(npm)
Apr 28, 2025
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
Low
CVE-2025-46328
was published
for
snowflake-sdk
(npm)
Apr 28, 2025
Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content
Low
CVE-2025-46653
was published
for
formidable
(npm)
Apr 26, 2025
GraphQL Armor Cost-Limit Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-733v-p3h5-qpq7
was published
for
@escape.tech/graphql-armor-cost-limit
(npm)
Apr 25, 2025
React Router allows pre-render data spoofing on React-Router framework mode
High
CVE-2025-43865
was published
for
react-router
(npm)
Apr 24, 2025
React Router allows a DoS via cache poisoning by forcing SPA mode
High
CVE-2025-43864
was published
for
react-router
(npm)
Apr 24, 2025
tRPC 11 WebSocket DoS Vulnerability
High
CVE-2025-43855
was published
for
@trpc/server
(npm)
Apr 24, 2025
PostHog Plugin Server SQL Injection Vulnerability
High
CVE-2025-1520
was published
for
@posthog/plugin-server
(npm)
Apr 23, 2025
ProTip!
Advisories are also available from the
GraphQL API