GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,556
Maven
5,000+
npm
4,226
NuGet
747
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,214 advisories
Filter by severity
Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Critical
CVE-2025-55315
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Oct 14, 2025
CometBFT's invalid BitArray handling can lead to network halt
High
GHSA-hrhf-2vcr-ghch
was published
for
github.com/cometbft/cometbft
(Go)
Oct 14, 2025
Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
Low
CVE-2025-62366
was published
for
mailgen
(npm)
Oct 14, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Moderate
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
Argo Workflow may expose artifact repository credentials
High
CVE-2025-62157
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Apache Geode web-api is vulnerable to Cross-site Scripting
Moderate
CVE-2024-44088
was published
for
org.apache.geode:geode-web-api
(Maven)
Oct 14, 2025
LibreNMS is vulnerable to Reflected-XSS in `report_this` function
Moderate
CVE-2025-62365
was published
for
librenms/librenms
(Composer)
Oct 13, 2025
Liferay Mentions Web is Vulnerable to Cross-site Scripting
Moderate
CVE-2025-62246
was published
for
com.liferay:com.liferay.mentions.web
(Maven)
Oct 13, 2025
Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62242
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62241
was published
for
com.liferay.commerce:com.liferay.commerce.order.content.web
(Maven)
Oct 13, 2025
Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62252
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 13, 2025
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Moderate
CVE-2025-59836
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
Moderate
CVE-2025-62244
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
High
CVE-2025-11695
was published
for
mongodb
(Rust)
Oct 13, 2025
Liferay Publications is vulnerable to Incorrect Authorization
Moderate
CVE-2025-62243
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
llama-index has Insecure Temporary File
High
CVE-2025-7707
was published
for
llama-index
(pip)
Oct 13, 2025
CommandKit has incorrect command name exposure in context object for message command aliases
Moderate
GHSA-fhwm-pc6r-4h2f
was published
for
commandkit
(npm)
Oct 13, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
QGIS QWC2 Cross-Site Scripting vulnerability
Moderate
CVE-2025-11183
was published
for
qwc2
(npm)
Oct 13, 2025
cel-rust May Panic During Parsing of Invalid CEL Expressions
High
CVE-2025-62162
was published
for
cel
(Rust)
Oct 11, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
Parallax is vulnerable to DoS via malicious p2p message
High
GHSA-xc79-566c-j4qx
was published
for
github.com/microstack-tech/parallax
(Go)
Oct 10, 2025
ProTip!
Advisories are also available from the
GraphQL API