GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,722
Maven
5,000+
npm
4,330
NuGet
762
pip
4,107
Pub
12
RubyGems
960
Rust
1,066
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,926 advisories
Filter by severity
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
CVE-2025-66622
was published
for
matrix-sdk-base
(Rust)
Dec 8, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Next.js is vulnerable to RCE in React flight protocol
Critical
GHSA-9qr9-h5gf-34mp
was published
for
next
(npm)
Dec 3, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
Moderate
CVE-2025-66470
was published
for
nicegui
(pip)
Dec 8, 2025
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
Moderate
CVE-2025-66469
was published
for
nicegui
(pip)
Dec 8, 2025
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
Critical
CVE-2025-65964
was published
for
n8n
(npm)
Dec 8, 2025
React Server Components are Vulnerable to RCE
Critical
GHSA-fmh4-wr37-44fp
was published
for
@vitejs/plugin-rsc
(npm)
Dec 3, 2025
WildFly improper RBAC permission
Moderate
CVE-2025-23367
was published
for
org.wildfly.core:wildfly-server
(Maven)
Jan 31, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Moderate
CVE-2025-66578
was published
for
robrichards/xmlseclibs
(Composer)
Dec 8, 2025
Fiber Utils UUIDv4 and UUID Silent Fallback to Predictable Values
Critical
CVE-2025-66565
was published
for
github.com/gofiber/utils
(Go)
Dec 8, 2025
1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers
Moderate
CVE-2025-66508
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Moderate
CVE-2025-66491
was published
for
github.com/traefik/traefik/v3
(Go)
Dec 8, 2025
Path Normalization Bypass in Traefik Router + Middleware Rules
Moderate
CVE-2025-66490
was published
for
github.com/traefik/traefik
(Go)
Dec 8, 2025
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Moderate
CVE-2025-66202
was published
for
astro
(npm)
Dec 8, 2025
Emby Server API Vulnerability allowing to gain administrative access without precondition
Critical
CVE-2025-64113
was published
for
MediaBrowser.Server.Core
(NuGet)
Dec 8, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
ComposioHQ has a directory traversal vulnerability
Moderate
CVE-2025-56427
was published
for
composio
(pip)
Dec 4, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionality
High
CVE-2025-65346
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 4, 2025
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
Mattermost Server allows attackers to create buttons that can launch API requests
Moderate
CVE-2017-18890
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to webhook and slash command manipulation
Moderate
CVE-2017-18889
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
Critical
CVE-2017-18888
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API