GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,755
Maven
5,000+
npm
4,359
NuGet
765
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,055 advisories
Filter by severity
filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
Moderate
CVE-2025-68146
was published
for
filelock
(pip)
Dec 16, 2025
PyMdown Extensions has a ReDOS bug in its Figure Capture extension
Low
CVE-2025-68142
was published
for
pymdown-extensions
(pip)
Dec 16, 2025
Libredesk has Improper Neutralization of HTML Tags in a Web Page
High
GHSA-wh6m-h6f4-rjf4
was published
for
github.com/abhinavxd/libredesk
(Go)
Dec 16, 2025
tRPC has possible prototype pollution in `experimental_nextAppDirCaller`
High
CVE-2025-68130
was published
for
@trpc/server
(npm)
Dec 16, 2025
Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables
Moderate
CVE-2025-68115
was published
for
parse-server
(npm)
Dec 16, 2025
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Moderate
CVE-2025-68113
was published
for
altcha
(RubyGems)
Dec 16, 2025
Fickling has Code Injection vulnerability via pty.spawn()
High
CVE-2025-67748
was published
for
fickling
(pip)
Dec 15, 2025
Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
High
CVE-2025-67747
was published
for
fickling
(pip)
Dec 15, 2025
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
Moderate
CVE-2025-67735
was published
for
io.netty:netty-codec-http
(Maven)
Dec 15, 2025
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)
Moderate
CVE-2025-67715
was published
for
Weblate
(pip)
Dec 15, 2025
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
Moderate
CVE-2025-67492
was published
for
Weblate
(pip)
Dec 15, 2025
LikeC4 has RCE through vulnerable React and Next.js versions
Critical
GHSA-vr6p-vq2p-6j74
was published
for
likec4
(npm)
Dec 15, 2025
Misskey has a login rate limit bypass via spoofed X-Forwarded-For header
Moderate
CVE-2025-66482
was published
for
misskey-js
(npm)
Dec 15, 2025
misskey.js's export data contains private post data
High
CVE-2025-66402
was published
for
misskey-js
(npm)
Dec 15, 2025
Weblate has improper validation upon invitation acceptance
Low
CVE-2025-64725
was published
for
Weblate
(pip)
Dec 15, 2025
Misconfigured Internal Proxy in runtimes-inventory-rhel8-operator Grants Standard Users Full Cluster Administrator Access
High
CVE-2025-11393
was published
for
github.com/RedHatInsights/runtimes-inventory-operator
(Go)
Dec 15, 2025
OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources
Critical
CVE-2025-13888
was published
for
github.com/redhat-developer/gitops-operator
(Go)
Dec 15, 2025
django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisions
Moderate
CVE-2025-65431
was published
for
django-allauth
(pip)
Dec 15, 2025
django-allauth does not reject access tokens for inactive users
Moderate
CVE-2025-65430
was published
for
django-allauth
(pip)
Dec 15, 2025
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Moderate
CVE-2025-37731
was published
for
org.elasticsearch:elasticsearch
(Maven)
Dec 15, 2025
Apache Airflow exposes secret values to authenticated UI users via rendered templates
Moderate
CVE-2025-66388
was published
for
apache-airflow
(pip)
Dec 15, 2025
kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass
Moderate
CVE-2025-13281
was published
for
k8s.io/kubernetes
(Go)
Dec 15, 2025
Mayan EDMS has an Open Redirect through the /authentication/ file
Low
CVE-2025-14692
was published
for
mayan-edms
(pip)
Dec 15, 2025
Mayan EDMS is vulnerable to XSS through the /authentication/ file
Low
CVE-2025-14691
was published
for
mayan-edms
(pip)
Dec 15, 2025
snail-job is vulnerable to Code Injection through QLExpressEngine.doEval function
Moderate
CVE-2025-14674
was published
for
com.aizuda:snail-job
(Maven)
Dec 14, 2025
ProTip!
Advisories are also available from the
GraphQL API