GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,770
NuGet
680
pip
3,458
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
7,579 advisories
Filter by severity
WhoDB allows parameter injection in DB connection URIs leading to local file inclusion
High
CVE-2025-24787
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
Mitmweb API Authentication Bypass Using Proxy Server
High
CVE-2025-23217
was published
for
mitmproxy
(pip)
Feb 6, 2025
pgAdmin has Incorrect Default Permissions
High
CVE-2023-1907
was published
for
pgadmin4
(pip)
Jan 9, 2025
Apache James vulnerable to denial of service through the use of IMAP literals
High
CVE-2024-37358
was published
for
org.apache.james.protocols:protocols-imap
(Maven)
Feb 6, 2025
Netplex Json-smart Uncontrolled Recursion vulnerability
High
CVE-2024-57699
was published
for
net.minidev:json-smart
(Maven)
Feb 6, 2025
SnakeYaml Constructor Deserialization Remote Code Execution
High
CVE-2022-1471
was published
for
org.yaml:snakeyaml
(Maven)
Dec 12, 2022
cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
High
CVE-2024-26130
was published
for
cryptography
(pip)
Feb 21, 2024
Contrast's unauthenticated recovery allows Coordinator impersonation
High
GHSA-vqv5-385r-2hf8
was published
for
github.com/edgelesssys/contrast
(Go)
Feb 5, 2025
MarbleRun unauthenticated recovery allows Coordinator impersonation
High
GHSA-w7wm-2425-7p2h
was published
for
github.com/edgelesssys/marblerun
(Go)
Feb 4, 2025
json-smart Uncontrolled Recursion vulnerability
High
CVE-2023-1370
was published
for
net.minidev:json-smart
(Maven)
Mar 23, 2023
HTTPie allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack
High
CVE-2023-48052
was published
for
httpie
(pip)
Nov 16, 2023
Buildah allows build breakout using malicious Containerfiles and concurrent builds
High
CVE-2024-11218
was published
for
github.com/containers/buildah
(Go)
Jan 21, 2025
OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalation
High
CVE-2024-25133
was published
for
github.com/openshift/hive
(Go)
Dec 31, 2024
MobSF Stored Cross-Site Scripting (XSS)
High
CVE-2025-24803
was published
for
mobsf
(pip)
Feb 5, 2025
CKAN has an XSS vector in user uploaded images in group/org and user profiles
High
CVE-2025-24372
was published
for
ckan
(pip)
Feb 5, 2025
Cockpit Arbitrary File Upload
High
CVE-2025-1025
was published
for
cockpit-hq/cockpit
(Composer)
Feb 5, 2025
Browsershot Path Traversal
High
CVE-2025-1022
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar arithmetic
High
CVE-2023-26557
was published
for
github.com/binance-chain/tss-lib
(Go)
Apr 21, 2023
CometBFT allows a malicious peer to stall the network by disseminating seemingly valid block parts
High
GHSA-r3r4-g7hq-pq4f
was published
for
github.com/cometbft/cometbft
(Go)
Feb 3, 2025
Sparkle Signing Checks Bypass
High
CVE-2025-0509
was published
for
github.com/sparkle-project/Sparkle
(Swift)
Feb 4, 2025
Withdrawn Advisory: Access control issues in blackbox_exporter
High
CVE-2023-26735
was published
for
github.com/prometheus/blackbox_exporter
(Go)
Apr 26, 2023
•
withdrawn
crossbeam-utils Unsoundness of AtomicCell<{i,u}64> arithmetics on 32-bit targets that support Atomic{I,U}64
High
CVE-2022-23639
was published
for
crossbeam-utils
(Rust)
Feb 16, 2022
Insufficient token expiration in Serenity
High
CVE-2023-31287
was published
for
Serenity.Net.Core
(NuGet)
Apr 27, 2023
ProTip!
Advisories are also available from the
GraphQL API