GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,228
Maven
5,000+
npm
3,895
NuGet
701
pip
3,661
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,896 advisories
Filter by severity
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
Moderate
CVE-2025-32388
was published
for
@sveltejs/kit
(npm)
Apr 14, 2025
Directus inserts access token from query string into logs
Moderate
CVE-2024-47822
was published
for
@directus/api
(npm)
Apr 14, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Moderate
CVE-2025-32379
was published
for
koa
(npm)
Apr 9, 2025
crud-query-parser SQL Injection vulnerability
High
CVE-2025-32020
was published
for
crud-query-parser
(npm)
Apr 9, 2025
Flowise Vulnerable to SQL Injection via `tableName` Parameter
High
CVE-2025-29189
was published
for
flowise-components
(npm)
Apr 9, 2025
ts-asn1-der has Incorrect DER Encoding of Numbers Leading to Denial of Service and Incorrect Value Representation
Moderate
CVE-2025-32029
was published
for
@apeleghq/asn1-der
(npm)
Apr 7, 2025
estree-util-value-to-estree allows prototype pollution in generated ESTree
Moderate
CVE-2025-32014
was published
for
estree-util-value-to-estree
(npm)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32031
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32030
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
FlowiseDB vulnerable to SQL Injection by authenticated users
Moderate
GHSA-9c4c-g95m-c8cp
was published
for
flowise
(npm)
Apr 7, 2025
js-object-utilities Vulnerable to Prototype Pollution
High
CVE-2025-28269
was published
for
js-object-utilities
(npm)
Apr 7, 2025
tarteaucitron.js allows url scheme injection via unfiltered inputs
Moderate
CVE-2025-31476
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
tarteaucitron.js allows prototype pollution via custom text injection
Moderate
CVE-2025-31475
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
tarteaucitron.js allows UI manipulation via unrestricted CSS injection
Moderate
CVE-2025-31138
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework
High
CVE-2025-31119
was published
for
generator-jhipster-entity-audit
(npm)
Apr 4, 2025
expand-object Vulnerable to Prototype Pollution via the expand() Function
Moderate
CVE-2025-3197
was published
for
expand-object
(npm)
Apr 4, 2025
bigint-buffer Vulnerable to Buffer Overflow via toBigIntLE() Function
High
CVE-2025-3194
was published
for
bigint-buffer
(npm)
Apr 4, 2025
React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
Low
CVE-2025-3191
was published
for
react-draft-wysiwyg
(npm)
Apr 4, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
CVE-2025-31477
was published
for
@tauri-apps/plugin-shell
(npm)
Apr 2, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
image-size Denial of Service via Infinite Loop during Image Processing
High
GHSA-m5qc-5hw7-8vg7
was published
for
image-size
(npm)
Apr 2, 2025
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
High
CVE-2025-31137
was published
for
@react-router/express
(npm)
Apr 1, 2025
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-929m-phjg-qwcc
was published
for
mathlive
(npm)
Apr 1, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API