GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
305,525 advisories
Filter by severity
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack
due to the absence of...
High
Unreviewed
CVE-2025-13970
was published
Dec 13, 2025
A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an...
Moderate
Unreviewed
CVE-2025-14582
was published
Dec 13, 2025
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-14584
was published
Dec 13, 2025
A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2025-14583
was published
Dec 13, 2025
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-14585
was published
Dec 13, 2025
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Unknown
Unreviewed
CVE-2025-14066
was published
Dec 13, 2025
Vuetify has a Prototype Pollution vulnerability
High
CVE-2025-8083
was published
for
vuetify
(npm)
Dec 12, 2025
Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component
Moderate
CVE-2025-8082
was published
for
vuetify
(npm)
Dec 12, 2025
MineAdmin has an insecure default password
Critical
CVE-2025-65854
was published
for
mineadmin/mineadmin
(Composer)
Dec 12, 2025
Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations
High
CVE-2025-3586
was published
for
com.liferay:com.liferay.object.service
(Maven)
Dec 12, 2025
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
High
CVE-2025-67721
was published
for
io.airlift:aircompressor-v3
(Maven)
Dec 12, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule
High
CVE-2025-67750
was published
for
lightning-flow-scanner
(npm)
Dec 12, 2025
Apache StreamPark uses a Weak Encryption Algorithm
High
CVE-2025-54981
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
Apache StreamPark has a hard-coded encryption key
High
CVE-2025-54947
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-67341
was published
Dec 12, 2025
Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core...
Moderate
Unreviewed
CVE-2025-64011
was published
Dec 12, 2025
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote...
Moderate
Unreviewed
CVE-2025-14372
was published
Dec 12, 2025
RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu...
Moderate
Unreviewed
CVE-2025-67342
was published
Dec 12, 2025
Plesk 18.0 has Incorrect Access Control.
Critical
Unreviewed
CVE-2025-66430
was published
Dec 12, 2025
jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the ...
Moderate
Unreviewed
CVE-2025-67344
was published
Dec 12, 2025
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php...
Moderate
Unreviewed
CVE-2025-55816
was published
Dec 11, 2025
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: fix use...
High
Unreviewed
CVE-2025-39863
was published
Sep 22, 2025
In the Linux kernel, the following vulnerability has been resolved:
ice: fix NULL access of tx-...
High
Unreviewed
CVE-2025-39855
was published
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API