GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
287,852 advisories
Filter by severity
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2...
High
Unreviewed
CVE-2025-54564
was published
Aug 1, 2025
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm...
Moderate
Unreviewed
CVE-2025-53713
was published
Jul 29, 2025
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm...
Moderate
Unreviewed
CVE-2025-53714
was published
Jul 29, 2025
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm...
Moderate
Unreviewed
CVE-2025-53712
was published
Jul 29, 2025
A vulnerability has been found in TP-Link TL-WR841N V11. The vulnerability exists in the /userRpm...
Moderate
Unreviewed
CVE-2025-53711
was published
Jul 29, 2025
io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
High
CVE-2025-1634
was published
for
io.quarkus:quarkus-resteasy
(Maven)
Feb 26, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Moderate
CVE-2025-6037
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Moderate
CVE-2025-6015
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Moderate
CVE-2025-6014
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users
Low
CVE-2025-6011
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Moderate
CVE-2025-6004
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High
CVE-2025-5999
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration
Critical
CVE-2025-6000
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Microweber XSS Vulnerability in the homepage Endpoint
Moderate
CVE-2025-51504
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the layout Parameter
Moderate
CVE-2025-51502
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the id Parameter
Moderate
CVE-2025-51501
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Withdrawn Advisory: ReDoS in py library when used with subversion
High
CVE-2022-42969
was published
for
py
(pip)
Oct 16, 2022
•
withdrawn
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
High
CVE-2025-30167
was published
for
jupyter_core
(pip)
Jun 4, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
CVE-2025-53605
was published
for
protobuf
(Rust)
Mar 7, 2025
Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
GHSA-rxf6-323f-44fc
was published
for
protobuf
(Rust)
Jul 5, 2025
•
withdrawn
@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS Developers
Critical
CVE-2025-54782
was published
for
@nestjs/devtools-integration
(npm)
Aug 1, 2025
webfinger.js Blind SSRF Vulnerability
Moderate
CVE-2025-54590
was published
for
webfinger.js
(npm)
Jul 28, 2025
MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
Moderate
CVE-2025-53012
was published
for
MaterialX
(pip)
Jul 31, 2025
MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput
Low
CVE-2025-53011
was published
for
MaterialX
(pip)
Jul 31, 2025
MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return
Low
CVE-2025-53010
was published
for
MaterialX
(pip)
Jul 31, 2025
ProTip!
Advisories are also available from the
GraphQL API