GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,051 advisories
Filter by severity
Next has a Denial of Service with Server Components - Incomplete Fix Follow-Up
High
GHSA-5j59-xgg2-r9c4
was published
for
next
(npm)
Dec 12, 2025
Vite Plugin React has a Source Code Exposure Vulnerability in React Server Components
Moderate
GHSA-c6m7-q6pr-c64r
was published
for
@vitejs/plugin-rsc
(npm)
Dec 12, 2025
Vite Plugin React has a Denial of Service Vulnerability in React Server Components
High
GHSA-cpqf-f22c-r95x
was published
for
@vitejs/plugin-rsc
(npm)
Dec 12, 2025
Denial of Service Vulnerability in React Server Components
High
CVE-2025-67779
was published
for
react-server-dom-parcel
(npm)
Dec 12, 2025
Apache HugeGraph-Server: RAFT and deserialization vulnerability
High
CVE-2025-26866
was published
for
org.apache.hugegraph:hg-pd-core
(Maven)
Dec 12, 2025
The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions...
High
Unreviewed
CVE-2025-14044
was published
Dec 12, 2025
Next Server Actions Source Code Exposure
Moderate
GHSA-w37m-7fhw-fmv9
was published
for
next
(npm)
Dec 11, 2025
Next Vulnerable to Denial of Service with Server Components
High
GHSA-mwv6-3258-q52c
was published
for
next
(npm)
Dec 11, 2025
Denial of Service Vulnerability in React Server Components
High
CVE-2025-55184
was published
for
react-server-dom-parcel
(npm)
Dec 11, 2025
Source Code Exposure Vulnerability in React Server Components
Moderate
CVE-2025-55183
was published
for
react-server-dom-parcel
(npm)
Dec 11, 2025
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1,...
Critical
Unreviewed
CVE-2025-34394
was published
Dec 10, 2025
A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion.
A user with...
High
Unreviewed
CVE-2025-9571
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of...
High
Unreviewed
CVE-2025-61810
was published
Dec 10, 2025
NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could...
High
Unreviewed
CVE-2025-33214
was published
Dec 9, 2025
NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where...
High
Unreviewed
CVE-2025-33213
was published
Dec 9, 2025
Deserialization of Untrusted Data vulnerability in WePlugins - WordPress Development Company WP...
Moderate
Unreviewed
CVE-2025-67535
was published
Dec 9, 2025
Under certain conditions, a high privileged user could exploit a deserialization vulnerability in...
Critical
Unreviewed
CVE-2025-42928
was published
Dec 9, 2025
Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)
High
CVE-2025-66631
was published
for
Csla
(NuGet)
Dec 8, 2025
HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component allowing attackers to achieve...
High
Unreviewed
CVE-2025-63721
was published
Dec 8, 2025
UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in...
Critical
Unreviewed
CVE-2025-66571
was published
Dec 4, 2025
React Server Components are Vulnerable to RCE
Critical
GHSA-fmh4-wr37-44fp
was published
for
@vitejs/plugin-rsc
(npm)
Dec 3, 2025
React Server Components are Vulnerable to RCE
Critical
CVE-2025-55182
was published
for
react-server-dom-parcel
(npm)
Dec 3, 2025
Next.js is vulnerable to RCE in React flight protocol
Critical
GHSA-9qr9-h5gf-34mp
was published
for
next
(npm)
Dec 3, 2025
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a...
High
Unreviewed
CVE-2025-41700
was published
Dec 1, 2025
The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
Moderate
Unreviewed
CVE-2025-9191
was published
Nov 26, 2025
ProTip!
Advisories are also available from the
GraphQL API