GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,638
Erlang
34
GitHub Actions
26
Go
2,249
Maven
5,000+
npm
3,903
NuGet
702
pip
3,671
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
128,600 advisories
Filter by severity
Harden-Runner allows evasion of 'disable-sudo' policy
Moderate
CVE-2025-32955
was published
for
step-security/harden-runner
(GitHub Actions)
Apr 22, 2025
A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic....
Moderate
Unreviewed
CVE-2025-3843
was published
Apr 22, 2025
A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0....
Moderate
Unreviewed
CVE-2025-3849
was published
Apr 22, 2025
A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-3845
was published
Apr 22, 2025
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical....
Moderate
Unreviewed
CVE-2025-3846
was published
Apr 22, 2025
A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This...
Moderate
Unreviewed
CVE-2025-3847
was published
Apr 22, 2025
Minio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STS
Moderate
CVE-2025-32963
was published
for
github.com/minio/operator
(Go)
Apr 21, 2025
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to...
Moderate
Unreviewed
CVE-2025-3841
was published
Apr 21, 2025
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects...
Moderate
Unreviewed
CVE-2025-3842
was published
Apr 21, 2025
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute...
Moderate
Unreviewed
CVE-2025-28102
was published
Apr 21, 2025
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller -...
Moderate
Unreviewed
CVE-2025-28367
was published
Apr 21, 2025
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management...
Moderate
Unreviewed
CVE-2024-12543
was published
Apr 21, 2025
In Cilium, packets from terminating endpoints may not be encrypted in Wireguard-enabled clusters
Moderate
CVE-2025-32793
was published
for
github.com/cilium/cilium
(Go)
Apr 21, 2025
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux...
Moderate
Unreviewed
CVE-2024-12863
was published
Apr 21, 2025
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in...
Moderate
Unreviewed
CVE-2025-28121
was published
Apr 21, 2025
Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux...
Moderate
Unreviewed
CVE-2024-12862
was published
Apr 21, 2025
OpenCMS cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-41446
was published
for
org.opencms:opencms-core
(Maven)
Apr 21, 2025
A vulnerability classified as critical was found in symisc UnQLite up to...
Moderate
Unreviewed
CVE-2025-3791
was published
Apr 21, 2025
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This...
Moderate
Unreviewed
CVE-2025-3792
was published
Apr 21, 2025
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper...
Moderate
Unreviewed
CVE-2025-2950
was published
Apr 21, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based...
Moderate
Unreviewed
CVE-2025-3837
was published
Apr 21, 2025
An Improper Authorization vulnerability was identified in the EOL OVA based connect component...
Moderate
Unreviewed
CVE-2025-3838
was published
Apr 21, 2025
GoBGP crashes in the flowspec parser
Moderate
CVE-2025-43972
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
GoBGP does not verify that the input length
Moderate
CVE-2025-43973
was published
for
github.com/osrg/gobgp
(Go)
Apr 21, 2025
ProTip!
Advisories are also available from the
GraphQL API