GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,912 advisories
Filter by severity
ComposioHQ has a directory traversal vulnerability
Moderate
CVE-2025-56427
was published
for
composio
(pip)
Dec 4, 2025
alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip/extraction functionality
High
CVE-2025-65346
was published
for
alexusmai/laravel-file-manager
(Composer)
Dec 4, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
Mattermost Server allows attackers to create buttons that can launch API requests
Moderate
CVE-2017-18890
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to webhook and slash command manipulation
Moderate
CVE-2017-18889
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
Critical
CVE-2017-18888
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server exposes team creator's e-mail address to other members
Moderate
CVE-2017-18887
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server does not properly restrict use of slash commands
High
CVE-2017-18886
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
Critical
CVE-2017-18885
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Apache SkyWalking has a stored XSS vulnerability
Moderate
CVE-2025-54057
was published
for
org.apache.skywalking:apm-webapp
(Maven)
Nov 27, 2025
Podman Creates Temporary File with Insecure Permissions
High
CVE-2025-4953
was published
for
github.com/containers/podman/v5
(Go)
Sep 16, 2025
Ansible Community General Collection is vulnerable to exposure of sensitive information
Moderate
CVE-2025-14010
was published
for
ansible
(pip)
Dec 4, 2025
LibreNMS Arbitrary File Read
Moderate
CVE-2017-16759
was published
for
librenms/librenms
(Composer)
May 13, 2022
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
Mattermost Server exposes OAuth personal access tokens to attackers
Critical
CVE-2017-18884
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server has low entropy for authorization data as an OAuth 2.0 Service Provider
Moderate
CVE-2017-18883
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
nitro-tpm-pcr-compute may allow kernel command line modification by an account operator
Moderate
GHSA-xrv8-2pf5-f3q7
was published
for
nitro-tpm-pcr-compute
(Rust)
Dec 5, 2025
yawkat LZ4 Java has a possible information leak in Java safe decompressor
High
CVE-2025-66566
was published
for
at.yawk.lz4:lz4-java
(Maven)
Dec 5, 2025
urllib3 streaming API improperly handles highly compressed data
High
CVE-2025-66471
was published
for
urllib3
(pip)
Dec 5, 2025
urllib3 allows an unbounded number of links in the decompression chain
High
CVE-2025-66418
was published
for
urllib3
(pip)
Dec 5, 2025
ROTP 6.2.2 and 6.2.1 has 0666 permissions for the .rb files.
Moderate
CVE-2024-28862
was published
for
rotp
(RubyGems)
Mar 18, 2024
LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
Moderate
CVE-2025-65093
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Sigstore Timestamp Authority allocates excessive memory during request parsing
High
CVE-2025-66564
was published
for
github.com/sigstore/timestamp-authority
(Go)
Dec 5, 2025
Fulcio allocates excessive memory during token parsing
High
CVE-2025-66506
was published
for
github.com/sigstore/fulcio
(Go)
Dec 5, 2025
ProTip!
Advisories are also available from the
GraphQL API