GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,781
Maven
5,000+
npm
4,386
NuGet
772
pip
4,164
Pub
12
RubyGems
965
Rust
1,073
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,183 advisories
Filter by severity
Trix has a stored XSS vulnerability through its attachment attribute
Moderate
GHSA-g9jg-w8vm-g96v
was published
for
action_text-trix
(RubyGems)
Dec 31, 2025
CBORDecoder reuse can leak shareable values across decode calls
Moderate
CVE-2025-68131
was published
for
cbor2
(pip)
Dec 31, 2025
theshit vulnerable to unsafe loading of user-owned Python rules when running as root
Moderate
CVE-2025-69257
was published
for
theshit
(Rust)
Dec 30, 2025
ImageMagick's failure to limit MVG mutual causes Stack Overflow
Moderate
CVE-2025-68950
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 30, 2025
ImageMagick's failure to limit the depth of SVG file reads caused a DoS attack
Moderate
CVE-2025-68618
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Dec 30, 2025
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
Moderate
CVE-2025-69202
was published
for
axios-cache-interceptor
(npm)
Dec 30, 2025
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Moderate
CVE-2025-69211
was published
for
@nestjs/platform-fastify
(npm)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
Moderate
GHSA-6556-fwc2-fg2p
was published
for
picklescan
(pip)
Dec 30, 2025
Visual Studio Code Go extension has unexpected untrusted code execution
Moderate
CVE-2025-68120
was published
for
github.com/golang/vscode-go
(Go)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
Moderate
GHSA-cffc-mxrf-mhh4
was published
for
picklescan
(pip)
Dec 29, 2025
phpMyFAQ has Stored XSS in user list via admin-managed display_name
Moderate
CVE-2025-68951
was published
for
thorsten/phpmyfaq
(Composer)
Dec 29, 2025
hemmelig allows SSRF Filter bypass via Secret Request functionality
Moderate
CVE-2025-69206
was published
for
hemmelig
(npm)
Dec 29, 2025
ruint affected by unsoundness of safe `reciprocal_mg10`
Moderate
GHSA-9fjq-45qv-pcm7
was published
for
ruint
(Rust)
Dec 26, 2025
Gitea vulnerable to Cross-site Scripting
Moderate
CVE-2025-68946
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order
Moderate
CVE-2025-68943
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea: anonymous user can visit private user's project
Moderate
CVE-2025-68945
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries
Moderate
CVE-2025-68944
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text
Moderate
CVE-2025-68942
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea mishandles authorization for deletion of releases
Moderate
CVE-2025-68938
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources
Moderate
CVE-2025-68941
was published
for
code.gitea.io/gitea
(Go)
Dec 26, 2025
Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
Moderate
CVE-2025-13767
was published
for
github.com/mattermost/mattermost-server
(Go)
Dec 24, 2025
Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin
Moderate
CVE-2025-64641
was published
for
github.com/mattermost/mattermost-server
(Go)
Dec 24, 2025
Home Assistant Core before is vulnerable to Directory Traversal
Moderate
CVE-2025-65713
was published
for
homeassistant
(pip)
Dec 23, 2025
LibreNMS Alert Rule API Cross-Site Scripting Vulnerability
Moderate
CVE-2025-68614
was published
for
librenms/librenms
(Composer)
Dec 23, 2025
Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
Moderate
CVE-2025-67743
was published
for
local-deep-research
(pip)
Dec 23, 2025
ProTip!
Advisories are also available from the
GraphQL API