GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,121
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,119 advisories
Filter by severity
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
Moderate
CVE-2025-67735
was published
for
io.netty:netty-codec-http
(Maven)
Dec 15, 2025
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)
Moderate
CVE-2025-67715
was published
for
Weblate
(pip)
Dec 15, 2025
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
Moderate
CVE-2025-67492
was published
for
Weblate
(pip)
Dec 15, 2025
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
Moderate
CVE-2025-66482
was published
for
misskey-js
(npm)
Dec 15, 2025
kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass
Moderate
CVE-2025-13281
was published
for
k8s.io/kubernetes
(Go)
Dec 15, 2025
snail-job is vulnerable to Code Injection through QLExpressEngine.doEval function
Moderate
CVE-2025-14674
was published
for
com.aizuda:snail-job
(Maven)
Dec 14, 2025
Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component
Moderate
CVE-2025-8082
was published
for
vuetify
(npm)
Dec 12, 2025
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components
Moderate
GHSA-c6m7-q6pr-c64r
was published
for
@vitejs/plugin-rsc
(npm)
Dec 12, 2025
Next Server Actions Source Code Exposure
Moderate
GHSA-w37m-7fhw-fmv9
was published
for
next
(npm)
Dec 11, 2025
Source Code Exposure Vulnerability in React Server Components
Moderate
CVE-2025-55183
was published
for
react-server-dom-parcel
(npm)
Dec 11, 2025
quic-go HTTP/3 QPACK Header Expansion DoS
Moderate
CVE-2025-64702
was published
for
github.com/quic-go/quic-go
(Go)
Dec 11, 2025
PowerJob has a server-side request forgery vulnerability in PingPongUtils.java
Moderate
CVE-2025-14518
was published
for
tech.powerjob:powerjob-common
(Maven)
Dec 11, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the panel name management functionality
Moderate
CVE-2025-34430
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
Improper Request Caching Lookup in the Auth0 Next.js SDK
Moderate
CVE-2025-67490
was published
for
@auth0/nextjs-auth0
(npm)
Dec 10, 2025
Improper Memory Cleanup in the Okta Java SDK
Moderate
CVE-2025-66033
was published
for
com.okta.sdk:okta-sdk-root
(Maven)
Dec 10, 2025
Pyrofork has a Path Traversal in download_media Method
Moderate
CVE-2025-67720
was published
for
pyrofork
(pip)
Dec 10, 2025
Algernon Cross-Site Scripting vulnerability
Moderate
CVE-2025-65754
was published
for
github.com/xyproto/algernon
(Go)
Dec 10, 2025
Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentials
Moderate
CVE-2025-67642
was published
for
com.datapipe.jenkins.plugins:hashicorp-vault-plugin
(Maven)
Dec 10, 2025
Jenkins Redpen - Pipeline Reporter for Jira Plugin has a path traversal vulnerability
Moderate
CVE-2025-67643
was published
for
org.jenkinsci.plugins:pipeline-reporter-by-redpen
(Maven)
Dec 10, 2025
Jenkins is missing a permission check on password fields
Moderate
CVE-2025-67636
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
Jenkins's build authorization token is stored and displayed in plain text
Moderate
CVE-2025-67637
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
Jenkins's build authorization token is stored and displayed in plain text
Moderate
CVE-2025-67638
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
Moderate
CVE-2025-67640
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Dec 10, 2025
sd changes the group ownership of the source file
Moderate
CVE-2025-65807
was published
for
sd
(Rust)
Dec 10, 2025
ProTip!
Advisories are also available from the
GraphQL API