GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,441
Maven
5,000+
npm
4,060
NuGet
723
pip
3,853
Pub
12
RubyGems
941
Rust
1,007
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,360 advisories
Filter by severity
Oak Server has ReDoS in x-forwarded-proto and x-forwarded-for headers
Moderate
CVE-2025-55152
was published
for
@oakserver/oak
(npm)
Aug 12, 2025
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
Moderate
CVE-2025-55159
was published
for
slab
(Rust)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Moderate
CVE-2025-54463
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Moderate
CVE-2025-53514
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-53910
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-54458
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-8285
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-48731
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-44001
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
TinyScientist has Path Traversal Vulnerability in PDF Review Function (CWE-22)
Moderate
CVE-2025-55149
was published
for
tiny-scientist
(pip)
Aug 11, 2025
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4581
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
Moderate
CVE-2025-4655
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Aug 9, 2025
Craft CMS has a theoretical bypass for CVE-2025-23209
Moderate
CVE-2025-54417
was published
for
craftcms/cms
(Composer)
Aug 8, 2025
Liferay Portal Reflected XSS in blogs-web
Moderate
CVE-2025-4576
was published
for
com.liferay:com.liferay.blogs.web
(Maven)
Aug 8, 2025
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
Moderate
CVE-2025-55001
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Moderate
CVE-2025-55003
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao TOTP Secrets Engine Code Reuse
Moderate
CVE-2025-55000
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Moderate
CVE-2025-54998
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Apache CXF: Untrusted JMS configuration can lead to RCE
Moderate
CVE-2025-48913
was published
for
org.apache.cxf:cxf-rt-transports-jms
(Maven)
Aug 8, 2025
ExecuTorch integer overflow vulnerability leads to code execution
Moderate
CVE-2025-54952
was published
for
executorch
(pip)
Aug 8, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
CVE-2025-54368
was published
for
uv
(pip)
Aug 7, 2025
Ollama allows deletion of arbitrary files
Moderate
CVE-2025-44779
was published
for
github.com/ollama/ollama
(Go)
Aug 7, 2025
Astros's duplicate trailing slash feature leads to an open redirection security issue
Moderate
CVE-2025-54793
was published
for
astro
(npm)
Aug 7, 2025
Keycloak-services SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Aug 6, 2025
ProTip!
Advisories are also available from the
GraphQL API