GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,767
Maven
5,000+
npm
4,373
NuGet
770
pip
4,145
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,120 advisories
Filter by severity
Fedify has ReDoS Vulnerability in HTML Parsing Regex
High
CVE-2025-68475
was published
for
@fedify/fedify
(npm)
Dec 22, 2025
Piranha has stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-67290
was published
for
Piranha
(NuGet)
Dec 22, 2025
Piranha has stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-67291
was published
for
Piranha
(NuGet)
Dec 22, 2025
Umbraco CMS has an arbitrary file upload vulnerability
Moderate
CVE-2025-67288
was published
for
Umbraco.Cms
(NuGet)
Dec 22, 2025
Marshmallow has DoS in Schema.load(many)
Moderate
CVE-2025-68480
was published
for
marshmallow
(pip)
Dec 22, 2025
KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential
High
CVE-2025-68476
was published
for
github.com/kedacore/keda/v2
(Go)
Dec 22, 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
Critical
CVE-2025-68613
was published
for
n8n
(npm)
Dec 22, 2025
Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplification
High
GHSA-83jg-m2pm-4jxj
was published
for
cowrie
(pip)
Dec 20, 2025
External Control of File Name or Path in Langflow
High
CVE-2025-68478
was published
for
langflow
(pip)
Dec 19, 2025
Langflow vulnerable to Server-Side Request Forgery
High
CVE-2025-68477
was published
for
langflow
(pip)
Dec 19, 2025
Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature
Low
GHSA-24v3-254g-jv85
was published
for
@tutao/tutanota-utils
(npm)
Dec 19, 2025
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
Moderate
CVE-2025-68481
was published
for
fastapi-users
(pip)
Dec 19, 2025
Orejime has executable code in HTML attributes
Low
CVE-2025-68457
was published
for
orejime
(npm)
Dec 19, 2025
pretix has Broken Access Control Allowing Cross-User File Access via UUID
Low
CVE-2025-14881
was published
for
pretix
(pip)
Dec 19, 2025
pretix has Broken Access Control Allowing Cross-User File Access via UUID
Low
CVE-2025-14882
was published
for
pretix
(pip)
Dec 19, 2025
Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
High
CVE-2025-66524
was published
for
org.apache.nifi:nifi-asana-processors
(Maven)
Dec 19, 2025
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
Moderate
CVE-2025-14546
was published
for
fastapi-sso
(pip)
Dec 19, 2025
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
Moderate
CVE-2025-68384
was published
for
org.elasticsearch.plugin:x-pack-security
(Maven)
Dec 19, 2025
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Moderate
CVE-2025-68383
was published
for
github.com/elastic/beats
(Go)
Dec 19, 2025
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
Moderate
CVE-2025-68390
was published
for
org.elasticsearch.plugin:x-pack-core
(Maven)
Dec 19, 2025
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments
High
CVE-2025-68388
was published
for
github.com/elastic/beats
(Go)
Dec 19, 2025
Weblate is vulnerable to RCE through Git config file overwrite
Critical
CVE-2025-68398
was published
for
Weblate
(pip)
Dec 18, 2025
Weblate has an arbitrary file read via symbolic links
High
CVE-2025-68279
was published
for
Weblate
(pip)
Dec 18, 2025
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
High
CVE-2025-53000
was published
for
nbconvert
(pip)
Dec 18, 2025
ProTip!
Advisories are also available from the
GraphQL API