GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,677 advisories
Filter by severity
Skuul School Management System has a Sensitive Data Exposure Vulnerability in Uploaded Images
Low
CVE-2025-13785
was published
for
yungifez/skuul
(Composer)
Nov 30, 2025
Skuul School Management System has an Insecure Direct Object Reference (IDOR) Vulnerability in View Fee Invoice
Low
CVE-2025-12918
was published
for
yungifez/skuul
(Composer)
Nov 9, 2025
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE
Low
CVE-2025-67737
was published
for
azuracast/azuracast
(Composer)
Dec 11, 2025
EverShop is vulnerable to Unauthorized Order Information Access (IDOR)
Low
CVE-2025-12919
was published
for
@evershop/evershop
(npm)
Nov 9, 2025
maxminddb's `Reader::open_mmap` unsoundly marks unsafe memmap operation as safe
Low
GHSA-mj73-j457-8x9q
was published
for
maxminddb
(Rust)
Dec 2, 2025
Improper Validation of Query Parameters in Auth0 Next.js SDK
Low
CVE-2025-67716
was published
for
@auth0/nextjs-auth0
(npm)
Dec 10, 2025
Envoy forwards early CONNECT data in TCP proxy mode
Low
CVE-2025-64763
was published
for
github.com/envoyproxy/envoy
(Go)
Dec 5, 2025
Jenkins has a CSRF vulnerability on the login form
Low
CVE-2025-67639
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
Low
CVE-2025-14082
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 10, 2025
@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)
Low
CVE-2025-14284
was published
for
@tiptap/extension-link
(npm)
Dec 9, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
CVE-2025-66622
was published
for
matrix-sdk-base
(Rust)
Dec 8, 2025
Duplicate Advisory: Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments
Low
GHSA-644f-hrff-mf96
was published
for
@nocobase/auth
(npm)
Dec 2, 2025
•
withdrawn
Better Auth's multi-session sign-out hook allows forged cookies to revoke arbitrary sessions
Low
GHSA-wmjr-v86c-m9jj
was published
for
better-auth
(npm)
Nov 26, 2025
yungifez Skuul School Management System vulnerable to XSS via SVG
Low
CVE-2025-13784
was published
for
yungifez/skuul
(Composer)
Nov 30, 2025
open-webui is Vulnerable to Incorrect Access Control
Low
CVE-2025-63681
was published
for
open-webui
(pip)
Dec 4, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal
Low
CVE-2025-65345
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 3, 2025
Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing
Low
CVE-2025-66479
was published
for
@anthropic-ai/sandbox-runtime
(npm)
Dec 4, 2025
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
Low
CVE-2025-66453
was published
for
org.mozilla:rhino
(Maven)
Dec 3, 2025
Contao is vulnerable to cross-site scripting in templates
Low
CVE-2025-65961
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
Mattermost fails to validate user permissions in Boards
Low
CVE-2025-13870
was published
for
github.com/mattermost/mattermost
(Go)
Dec 2, 2025
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
CVE-2025-65858
was published
for
calibreweb
(pip)
Dec 2, 2025
Withdrawn Advisory: express improperly controls modification of query properties
Low
CVE-2024-51999
was published
for
express
(npm)
Dec 1, 2025
•
withdrawn
Discovery uses the same AES/GCM Nonce throughout the session
Low
CVE-2024-23688
was published
for
tech.pegasys.discovery:discovery
(Maven)
Apr 6, 2021
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low
CVE-2025-48985
was published
for
ai
(npm)
Nov 7, 2025
Keycloak unable to restrict access to the admin console
Low
CVE-2025-10939
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API