GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
7,889 advisories
Filter by severity
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
High
CVE-2024-53305
was published
for
whoogle-search
(pip)
Apr 16, 2025
Kyverno vulnerable to SSRF via Service Calls
High
GHSA-459x-q9hg-4gpq
was published
for
github.com/kyverno/kyverno
(Go)
Apr 15, 2025
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
High
CVE-2025-3445
was published
for
github.com/mholt/archiver
(Go)
Apr 14, 2025
CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows
High
GHSA-f87w-3j5w-v58p
was published
for
CefSharp.OffScreen
(NuGet)
Apr 12, 2025
golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange
High
CVE-2025-22869
was published
for
golang.org/x/crypto
(Go)
Apr 12, 2025
SurrealDB CPU exhaustion via custom functions result in total DoS
High
GHSA-pxw4-94j3-v9pf
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
High
GHSA-3633-g6mg-p6qq
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
High
GHSA-rq86-9m6r-cm3g
was published
for
surrealdb
(Rust)
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
GHSA-6jrf-4jv4-r9mw
was published
for
tendermint-light-client-verifier
(Rust)
Apr 9, 2025
crud-query-parser SQL Injection vulnerability
High
CVE-2025-32020
was published
for
crud-query-parser
(npm)
Apr 9, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Flowise Vulnerable to SQL Injection via `tableName` Parameter
High
CVE-2025-29189
was published
for
flowise-components
(npm)
Apr 9, 2025
Joomla CMS Multi-Factor Authentication Bypass
High
CVE-2025-25227
was published
for
joomla/joomla-cms
(Composer)
Apr 8, 2025
Shopware Vulnerable to Blind SQL-injection in DAL aggregations
High
CVE-2025-27892
was published
for
shopware/core
(Composer)
Apr 8, 2025
Shopware allows Denial Of Service via password length
High
CVE-2025-30151
was published
for
shopware/core
(Composer)
Apr 8, 2025
Apollo Compiler Named Fragment Processing Vulnerability
High
CVE-2025-31496
was published
for
apollo-compiler
(Rust)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32031
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32030
was published
for
@apollo/gateway
(npm)
Apr 7, 2025
Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment Processing
High
CVE-2025-32380
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow
High
CVE-2025-32033
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
High
CVE-2025-32034
was published
for
apollo-router
(Rust)
Apr 7, 2025
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
High
CVE-2025-32032
was published
for
apollo-router
(Rust)
Apr 7, 2025
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
High
GHSA-93mv-x874-956g
was published
for
picklescan
(pip)
Apr 7, 2025
ProTip!
Advisories are also available from the
GraphQL API