GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,090 advisories
Filter by severity
OpenTofu incorrectly validates excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANs
Moderate
GHSA-mjcp-gpgx-ggcg
was published
for
github.com/opentofu/opentofu
(Go)
Dec 9, 2025
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality
Moderate
CVE-2025-66625
was published
for
Umbraco.Cms
(NuGet)
Dec 9, 2025
Singluarity ineffectively applies selinux / apparmor LSM process labels
Moderate
CVE-2025-64750
was published
for
github.com/sylabs/singularity/v4
(Go)
Dec 2, 2025
1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers
Moderate
CVE-2025-66508
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Moderate
CVE-2025-66578
was published
for
robrichards/xmlseclibs
(Composer)
Dec 8, 2025
Static Web Server vulnerable to a symbolic link path traversal
Moderate
CVE-2025-67487
was published
for
static-web-server
(Rust)
Dec 8, 2025
Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments
Moderate
CVE-2025-13877
was published
for
@nocobase/auth
(npm)
Dec 9, 2025
JDA (Java Discord API) downloads external URLs when updating message components
Moderate
GHSA-93fv-4pm9-xp28
was published
for
net.dv8tion:JDA
(Maven)
Dec 9, 2025
CNA Plugins Portmap nftables backend can intercept non-local traffic
Moderate
CVE-2025-67499
was published
for
github.com/containernetworking/plugins
(Go)
Dec 9, 2025
memos vulnerability allows arbitrarily modification or deletion registered identity providers
Moderate
CVE-2025-65797
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
HTTP/HTTPS Traffic Interception Bypass in mad-proxy
Moderate
CVE-2025-67485
was published
for
mad-proxy
(pip)
Dec 9, 2025
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Moderate
CVE-2025-66491
was published
for
github.com/traefik/traefik/v3
(Go)
Dec 8, 2025
Path Normalization Bypass in Traefik Router + Middleware Rules
Moderate
CVE-2025-66490
was published
for
github.com/traefik/traefik
(Go)
Dec 8, 2025
NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
Moderate
CVE-2025-66470
was published
for
nicegui
(pip)
Dec 8, 2025
NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
Moderate
CVE-2025-66469
was published
for
nicegui
(pip)
Dec 8, 2025
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Moderate
CVE-2025-66202
was published
for
astro
(npm)
Dec 8, 2025
Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)
Moderate
GHSA-9x4v-xfq5-m8x5
was published
for
better-auth
(npm)
Feb 5, 2025
Open Redirect Vulnerability in Taguette
Moderate
CVE-2025-67502
was published
for
taguette
(pip)
Dec 9, 2025
Altcha Proof-of-Work obfuscation mode cryptanalytic break
Moderate
CVE-2025-65849
was published
for
altcha
(npm)
Dec 8, 2025
memos lacks file name validation or verification
Moderate
CVE-2025-65799
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily modification or deletion of attachments
Moderate
CVE-2025-65798
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily reactions deletion
Moderate
CVE-2025-65796
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
Babylon Incorrect FP inactive accounting in costaking creates “phantom stake” that earns rewards after BTC unbond
Moderate
GHSA-4rmq-mc2c-r495
was published
for
github.com/babylonlabs-io/babylon
(Go)
Dec 9, 2025
WildFly improper RBAC permission
Moderate
CVE-2025-23367
was published
for
org.wildfly.core:wildfly-server
(Maven)
Jan 31, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
ProTip!
Advisories are also available from the
GraphQL API