GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
21,009 advisories
Filter by severity
GHSL-2024-288: SickChill open redirect in login
Low
CVE-2024-53995
was published
for
sickchill
(pip)
Jan 8, 2025
Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale
Moderate
CVE-2025-22145
was published
for
nesbot/carbon
(Composer)
Jan 8, 2025
Reportlab vulnerable to remote code execution
High
CVE-2023-33733
was published
for
reportlab
(pip)
Jun 5, 2023
Soft Serve vulnerable to path traversal attacks
Moderate
CVE-2025-22130
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2025
ZITADEL's Improper Content-Type Validation Leads to Account Takeover via Stored XSS + CSP Bypass
High
CVE-2024-29891
was published
for
github.com/zitadel/zitadel
(Go)
Mar 28, 2024
Improper HTML sanitization in ZITADEL
High
CVE-2024-28855
was published
for
github.com/zitadel/zitadel
(Go)
Mar 18, 2024
keras Path Traversal vulnerability
Moderate
CVE-2024-55459
was published
for
keras
(pip)
Jan 8, 2025
xml-rs vulnerable to denial of service via invalid token in XML document
High
CVE-2023-34411
was published
for
xml-rs
(Rust)
Jun 5, 2023
Apache OpenMeetings vulnerable to Deserialization of Untrusted Data
Critical
CVE-2024-54676
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
Jan 8, 2025
Apache Airflow Fab Provider Insufficient Session Expiration vulnerability
Low
CVE-2024-45033
was published
for
apache-airflow-providers-fab
(pip)
Jan 8, 2025
Jinja has a sandbox breakout through malicious filenames
Moderate
CVE-2024-56201
was published
for
jinja2
(pip)
Dec 23, 2024
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
High
CVE-2024-56337
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Dec 20, 2024
Taurus multi-party-sig has OT-based ECDSA protocol implementation flaws
High
GHSA-7f6p-phw2-8253
was published
for
github.com/taurusgroup/multi-party-sig
(Go)
Nov 25, 2024
Possible ReDoS vulnerability in block_format in Action Mailer
Moderate
CVE-2024-47889
was published
for
actionmailer
(RubyGems)
Oct 15, 2024
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
Moderate
CVE-2024-52813
was published
for
matrix-sdk-crypto
(Rust)
Jan 7, 2025
Snipe-IT remote code execution
High
CVE-2024-48987
was published
for
snipe/snipe-it
(Composer)
Oct 11, 2024
Account Takeover via Session Fixation in Zitadel [Bypassing MFA]
High
CVE-2024-28197
was published
for
github.com/zitadel/zitadel
(Go)
Mar 11, 2024
PHP-Textile has persistent XSS vulnerability in image link handling
High
GHSA-95m2-chm4-mq7m
was published
for
netcarver/textile
(Composer)
Jan 7, 2025
Next.js Allows a Denial of Service (DoS) with Server Actions
Moderate
CVE-2024-56332
was published
for
next
(npm)
Jan 3, 2025
WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover
High
GHSA-2r2v-9pf8-6342
was published
for
github.com/h44z/wg-portal
(Go)
Jan 7, 2025
Prototype pollution in jsii.configureCategories
Low
GHSA-m56h-5xx3-2jc2
was published
for
jsii
(npm)
Dec 18, 2024
fetch: Authorization headers not dropped when redirecting cross-origin
High
CVE-2025-21620
was published
for
deno
(Rust)
Jan 6, 2025
Elasticsearch Improper Access Control vulnerability
Moderate
CVE-2014-3120
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API