GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,830
Erlang
36
GitHub Actions
33
Go
2,449
Maven
5,000+
npm
4,066
NuGet
723
pip
3,868
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,512 advisories
Filter by severity
LibreNMS allows stored XSS in Alert Template name field
Moderate
CVE-2025-55296
was published
for
librenms/librenms
(Composer)
Aug 18, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-43731
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 18, 2025
Copier's safe template has filesystem write access outside destination path
Moderate
CVE-2025-55214
was published
for
copier
(pip)
Aug 18, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-55213
was published
for
github.com/openfga/openfga
(Go)
Aug 18, 2025
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
Critical
CVE-2025-55205
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 18, 2025
Copier's safe template has arbitrary filesystem read/write access
High
CVE-2025-55201
was published
for
copier
(pip)
Aug 18, 2025
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
High
CVE-2025-55284
was published
for
@anthropic-ai/claude-code
(npm)
Aug 18, 2025
Liferay Portal Login Bypass Vulnerability
Low
CVE-2025-3639
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 18, 2025
Liferay Portal Vulnerable to Insecure Direct Object Reference
Moderate
CVE-2025-43732
was published
for
com.liferay:com.liferay.roles.selector.web
(Maven)
Aug 18, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Low
CVE-2025-43733
was published
for
com.liferay:com.liferay.layout.taglib
(Maven)
Aug 18, 2025
IdMap from_iter may lead to uninitialized memory being freed on drop
Moderate
GHSA-qq4c-hm99-979m
was published
for
id-map
(Rust)
Aug 18, 2025
Spring Framework MVC Applications Path Traversal Vulnerability
Moderate
CVE-2025-41242
was published
for
org.springframework:spring-webmvc
(Maven)
Aug 18, 2025
HashiCorp go-getter Vulnerable to Symlink Attacks
High
CVE-2025-8959
was published
for
github.com/hashicorp/go-getter
(Go)
Aug 15, 2025
Template Secret leakage in logs in Scaffolder when using `fetch:template`
Low
CVE-2025-55285
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Aug 15, 2025
@astrojs/node's trailing slash handling causes open redirect issue
Moderate
CVE-2025-55207
was published
for
@astrojs/node
(npm)
Aug 15, 2025
User-defined implementations of the safe trait scratchpad::Tracking can cause heap buffer overflows
Moderate
GHSA-77h3-w9rx-hj3q
was published
for
scratchpad
(Rust)
Aug 14, 2025
Python-Future Module Arbitrary Code Execution via Unintended Import of test.py
High
CVE-2025-50817
was published
for
future
(pip)
Aug 14, 2025
Information Disclosure in Amazon ECS Container Agent
Moderate
CVE-2025-9039
was published
for
github.com/aws/amazon-ecs-agent
(Go)
Aug 14, 2025
Youki: If /proc and /sys in the rootfs are symbolic links, they can potentially be exploited to gain access to the host root filesystem.
High
CVE-2025-54867
was published
for
youki
(Rust)
Aug 14, 2025
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Moderate
CVE-2025-55675
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Moderate
CVE-2025-55674
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-55672
was published
for
apache-superset
(pip)
Aug 14, 2025
Apache Superset data query improperly discloses database schema information to low-privileged guest user
Moderate
CVE-2025-55673
was published
for
apache-superset
(pip)
Aug 14, 2025
Flowise OS command remote code execution
Critical
CVE-2025-8943
was published
for
flowise
(npm)
Aug 14, 2025
Flowise JS injection remote code execution
Critical
CVE-2025-55346
was published
for
flowise
(npm)
Aug 14, 2025
ProTip!
Advisories are also available from the
GraphQL API