GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,230 advisories
Filter by severity
uniapi version 1.0.7 contained an information harvesting script.
High
GHSA-gvvw-rr8m-fj76
was published
for
uniapi
(pip)
Jan 27, 2025
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
Moderate
CVE-2025-24361
was published
for
@nuxt/rspack-builder
(npm)
Jan 27, 2025
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
Moderate
CVE-2025-24360
was published
for
@nuxt/vite-builder
(npm)
Jan 27, 2025
Apache Solr Relative Path Traversal vulnerability
Moderate
CVE-2024-52012
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
Apache Solr vulnerable to Execution with Unnecessary Privileges
High
CVE-2025-24814
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
HL7 FHIR IG Publisher potentially exposes GitHub repo user and credential information
Moderate
CVE-2025-24363
was published
for
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli
(Maven)
Jan 24, 2025
ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
High
CVE-2025-24359
was published
for
asteval
(pip)
Jan 24, 2025
Updatecli exposes Maven credentials in console output
High
CVE-2025-24355
was published
for
github.com/updatecli/updatecli
(Go)
Jan 24, 2025
GitHub PAT written to debug artifacts
High
CVE-2025-24362
was published
for
github/codeql-action
(GitHub Actions)
Jan 24, 2025
XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`
High
CVE-2024-52807
was published
for
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli
(Maven)
Jan 24, 2025
Cross Site Scripting vulnerability in store2
Moderate
CVE-2024-57556
was published
for
store2
(npm)
Jan 24, 2025
Directus has a DOM-Based cross-site scripting (XSS) via layout_options
Low
GHSA-9qrm-48qf-r2rw
was published
for
directus
(npm)
Jan 23, 2025
Directus allows privilege escalation using Share feature
Moderate
CVE-2025-24353
was published
for
directus
(npm)
Jan 23, 2025
ASTEVAL Allows Malicious Tampering of Exposed AST Nodes Leads to Sandbox Escape
High
GHSA-vp47-9734-prjw
was published
for
asteval
(pip)
Jan 23, 2025
Unlimited consumption of resources in @fastify/multipart
High
CVE-2025-24033
was published
for
@fastify/multipart
(npm)
Jan 23, 2025
Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-74j9-xhqr-6qv3
was published
for
silverstripe/framework
(Composer)
Jan 23, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint
High
CVE-2025-24030
was published
for
github.com/envoyproxy/gateway
(Go)
Jan 23, 2025
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
High
CVE-2025-22153
was published
for
RestrictedPython
(pip)
Jan 23, 2025
Apache Wicket: An attacker can intentionally trigger a memory leak
Critical
CVE-2024-53299
was published
for
org.apache.wicket:wicket-core
(Maven)
Jan 23, 2025
phpMyAdmin XSS when checking tables
Moderate
CVE-2025-24530
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 23, 2025
Cross site scripting in Silverpeas Core
Moderate
CVE-2024-56923
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Jan 22, 2025
Missing permission checks in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24403
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy Plugin
Moderate
CVE-2025-24401
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Jan 22, 2025
CSRF vulnerability in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24402
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
High
CVE-2025-24398
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Jan 22, 2025
ProTip!
Advisories are also available from the
GraphQL API