GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,780
Erlang
36
GitHub Actions
29
Go
2,344
Maven
5,000+
npm
3,973
NuGet
719
pip
3,770
Pub
12
RubyGems
923
Rust
978
Swift
38
Unreviewed advisories
All unreviewed
5,000+
8,075 advisories
Filter by severity
Pingora has a Request Smuggling Vulnerability
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
Jun 20, 2025
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
High
CVE-2025-52488
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM possibly allows bypass of IP Filters
High
CVE-2025-52487
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
sentry-android unmasked sensitive data in Android Session Replays for users of Jetpack Compose 1.8+
High
GHSA-7cjh-xx4r-qh3f
was published
for
io.sentry:sentry-android
(Maven)
Jun 20, 2025
Crafter Studio Groovy Sandbox Bypass
High
CVE-2025-6384
was published
for
org.craftercms:crafter-studio
(Maven)
Jun 19, 2025
PowSyBl Core allows deserialization of untrusted SparseMatrix data
High
CVE-2025-47771
was published
for
com.powsybl:powsybl-math
(Maven)
Jun 19, 2025
DotVVM allows path traversal when deployed in Debug mode
High
GHSA-6q65-j4jw-9cg8
was published
for
DotVVM
(NuGet)
Jun 19, 2025
OpenNext for Cloudflare (opennextjs-cloudflare) has a SSRF vulnerability via /_next/image endpoint
High
CVE-2025-6087
was published
for
@opennextjs/cloudflare
(npm)
Jun 16, 2025
protobuf-python has a potential Denial of Service issue
High
CVE-2025-4565
was published
for
protobuf
(pip)
Jun 16, 2025
Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
High
CVE-2025-3594
was published
for
com.liferay:com.liferay.server.admin.web
(Maven)
Jun 16, 2025
Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
High
CVE-2025-3526
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Jun 16, 2025
Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers
High
CVE-2025-48976
was published
for
org.apache.commons:commons-fileupload2-core
(Maven)
Jun 16, 2025
Apache Tomcat - DoS in multipart upload
High
CVE-2025-48988
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jun 16, 2025
Liferay Portal does not limit the depth of a GraphQL queries
High
CVE-2025-3602
was published
for
com.liferay:com.liferay.portal.vulcan.impl
(Maven)
Jun 16, 2025
XWiki does not require right warnings for XClass definitions
High
CVE-2025-49585
was published
for
org.xwiki.platform:xwiki-platform-security-requiredrights-default
(Maven)
Jun 13, 2025
XWiki allows remote code execution through preview of XClass changes in AWM editor
High
CVE-2025-49586
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 13, 2025
XWiki makes title of inaccessible pages available through the class property values REST API
High
CVE-2025-49584
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 13, 2025
XWiki allows remote code execution through default value of wiki macro wiki-type parameters
High
CVE-2025-49581
was published
for
org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
(Maven)
Jun 13, 2025
XWiki's required right warnings for macros are incomplete
High
CVE-2025-49582
was published
for
org.xwiki.platform:xwiki-platform-rendering-macro-cache
(Maven)
Jun 13, 2025
XWiki allows privilege escalation through link refactoring
High
CVE-2025-49580
was published
for
org.xwiki.platform:xwiki-platform-refactoring-default
(Maven)
Jun 13, 2025
OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
High
CVE-2025-28382
was published
for
openc3-cosmos-tool-iframe
(RubyGems)
Jun 13, 2025
Salt has minion event bus authorization bypass vulnerability
High
CVE-2025-22236
was published
for
salt
(pip)
Jun 13, 2025
Salt vulnerable to arbitrary event injection
High
CVE-2025-22239
was published
for
salt
(pip)
Jun 13, 2025
Drupal Admin Audit Trail Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-48448
was published
for
drupal/admin_audit_trail
(Composer)
Jun 11, 2025
Drupal Commerce Alphabank Redirect Incorrect Authorization vulnerability
High
CVE-2025-48446
was published
for
drupal/commerce_alphabank_redirect
(Composer)
Jun 11, 2025
ProTip!
Advisories are also available from the
GraphQL API