GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,657 advisories
Filter by severity
Memos' Access Tokens Stay Valid after User Password Change
High
CVE-2024-21635
was published
for
github.com/usememos/memos
(Go)
Nov 14, 2025
Apollo Federation has Improper Enforcement of Access Control on Transitive Fields
High
GHSA-m8jr-fxqx-8xx6
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Duplicate Advisory: Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
High
GHSA-jj37-3377-m6vv
was published
for
nodemailer
(npm)
Nov 14, 2025
•
withdrawn
ZITADEL is vulnerable to Account Takeover with deactivated Instance IdP
High
CVE-2025-64717
was published
for
github.com/zitadel/zitadel
(Go)
Nov 14, 2025
Flowise does not Prevent Bypass of Password Confirmation - Unverified Password Change
High
GHSA-fjh6-8679-9pch
was published
for
flowise-ui
(npm)
Nov 14, 2025
Flowise doesn't Prevent Bypass of Password Confirmation through Unverified Email Change (credentials)
High
GHSA-x39m-3393-3qp4
was published
for
flowise-ui
(npm)
Nov 14, 2025
Flowise Fails to Invalidate Existing Sessions After Password Changes
High
GHSA-x7rp-qj2h-ghgw
was published
for
flowise
(npm)
Nov 14, 2025
expr-eval vulnerable to Prototype Pollution
High
CVE-2025-13204
was published
for
expr-eval
(npm)
Nov 14, 2025
@apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields
High
CVE-2025-64530
was published
for
@apollo/composition
(npm)
Nov 14, 2025
LXD vulnerable to a local privilege escalation through custom storage volumes
High
GHSA-3g2j-vm47-x4mj
was published
for
github.com/canonical/lxd
(Go)
Nov 13, 2025
ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-4249-gjr8-jpq3
was published
for
prosemirror_to_html
(RubyGems)
Nov 13, 2025
File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function
High
CVE-2025-64523
was published
for
github.com/filebrowser/filebrowser
(Go)
Nov 13, 2025
Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable
High
CVE-2025-59840
was published
for
vega
(npm)
Nov 13, 2025
AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
GHSA-8wj8-cfxr-9374
was published
for
aws-advanced-nodejs-wrapper
(npm)
Nov 13, 2025
AWS Advanced Go Wrapper: Privilege Escalation in Aurora PostgreSQL Instance
High
GHSA-7wq2-32h4-9hc9
was published
for
github.com/aws/aws-advanced-go-wrapper/awssql
(Go)
Nov 13, 2025
Amazon Web Services Advanced JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
GHSA-7xw4-g7mm-r4hh
was published
for
software.amazon.jdbc:aws-advanced-jdbc-wrapper
(Maven)
Nov 13, 2025
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
High
CVE-2025-12967
was published
for
aws_advanced_python_wrapper
(pip)
Nov 13, 2025
Incus vulnerable to local privilege escalation through custom storage volumes
High
CVE-2025-64507
was published
for
github.com/lxc/incus
(Go)
Nov 13, 2025
pgAdmin has vulnerability in LDAP authentication mechanism that allows bypassing TLS certificate verification
High
CVE-2025-12765
was published
for
pgadmin4
(pip)
Nov 13, 2025
pgAdmin is affected by an LDAP injection vulnerability
High
CVE-2025-12764
was published
for
pgadmin4
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
High
CVE-2025-64509
was published
for
bugsink
(pip)
Nov 13, 2025
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
High
CVE-2025-64508
was published
for
bugsink
(pip)
Nov 13, 2025
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
High
CVE-2025-64500
was published
for
symfony/http-foundation
(Composer)
Nov 12, 2025
Evervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted Enclaves
High
CVE-2025-64186
was published
for
github.com/evervault/evervault-go
(Go)
Nov 12, 2025
OAuth2-Proxy is vulnerable to header smuggling via underscore leading to potential privilege escalation
High
CVE-2025-64484
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Nov 12, 2025
ProTip!
Advisories are also available from the
GraphQL API