GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,214 advisories
Filter by severity
Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
Low
CVE-2024-55226
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Vaultwarden HTML injection vulnerability
Low
CVE-2024-55224
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Low
CVE-2025-22151
was published
for
strawberry-graphql
(pip)
Jan 9, 2025
JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh
Low
CVE-2025-22149
was published
for
github.com/MicahParks/jwkset
(Go)
Jan 9, 2025
Mattermost has Improper Check for Unusual or Exceptional Conditions
Low
CVE-2025-22445
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-22449
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
GHSL-2024-288: SickChill open redirect in login
Low
CVE-2024-53995
was published
for
sickchill
(pip)
Jan 8, 2025
Apache Airflow Fab Provider Insufficient Session Expiration vulnerability
Low
CVE-2024-45033
was published
for
apache-airflow-providers-fab
(pip)
Jan 8, 2025
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
magic-crypt uses insecure cryptographic algorithms
Low
GHSA-gmx7-gr5q-85w5
was published
for
magic-crypt
(Rust)
Dec 30, 2024
xous has unsound usages of `core::slice::from_raw_parts`
Low
GHSA-gv7f-5qqh-vxfx
was published
for
xous
(Rust)
Dec 30, 2024
Apache NiFi: Missing Complete Authorization for Parameter and Service References
Low
CVE-2024-56512
was published
for
org.apache.nifi:nifi-web-api
(Maven)
Dec 28, 2024
Oqtane Framework Insecure Direct Object Reference vulnerability
Low
CVE-2024-55186
was published
for
Oqtane.Client
(NuGet)
Dec 20, 2024
QOS.CH logback-core Server-Side Request Forgery vulnerability
Low
CVE-2024-12801
was published
for
ch.qos.logback:logback-core
(Maven)
Dec 19, 2024
Prototype pollution in jsii.configureCategories
Low
GHSA-m56h-5xx3-2jc2
was published
for
jsii
(npm)
Dec 18, 2024
Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
Low
CVE-2024-56128
was published
for
org.apache.kafka:kafka
(Maven)
Dec 18, 2024
SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Low
GHSA-27vq-hv74-7cqp
was published
for
surrealdb
(Rust)
Dec 16, 2024
sigstore has insufficient validation of integration timestamp during verification
Low
CVE-2024-55655
was published
for
sigstore
(pip)
Dec 11, 2024
Possible Content Security Policy bypass in Action Dispatch
Low
CVE-2024-54133
was published
for
actionpack
(RubyGems)
Dec 10, 2024
Simulation of Wasmd message can cause crashing
Low
GHSA-vmg2-r3xv-r3xf
was published
for
github.com/CosmWasm/wasmd
(Go)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
lxd CA certificate sign check bypass
Low
CVE-2024-6156
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
lxd has a restricted TLS certificate privilege escalation when in PKI mode
Low
CVE-2024-6219
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
Low
CVE-2024-53947
was published
for
apache-superset
(pip)
Dec 9, 2024
ProTip!
Advisories are also available from the
GraphQL API