GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,651
Erlang
34
GitHub Actions
26
Go
2,253
Maven
5,000+
npm
3,906
NuGet
703
pip
3,677
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
179 advisories
Filter by severity
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
Low
GHSA-qc59-cxj2-c2w4
was published
for
aws-cdk-lib
(npm)
Apr 15, 2025
cookie accepts cookie name, path, and domain with out of bounds characters
Low
CVE-2024-47764
was published
for
cookie
(npm)
Oct 4, 2024
AWS CDK CodePipeline: trusted entities are too broad
Low
GHSA-5pq3-h73f-66hr
was published
for
aws-cdk-lib
(npm)
Mar 24, 2025
React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button
Low
CVE-2025-3191
was published
for
react-draft-wysiwyg
(npm)
Apr 4, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Suspended Directus user can continue to use session token to access API
Low
CVE-2025-30351
was published
for
directus
(npm)
Mar 26, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
Mattermost Desktop App allows the bypass of Transparency, Consent, and Control (TCC) via code injection
Low
CVE-2025-1398
was published
for
mattermost-desktop
(npm)
Mar 17, 2025
seajs Cross-site Scripting vulnerability
Low
CVE-2024-51091
was published
for
seajs
(npm)
Mar 3, 2025
MongoDB Shell may be susceptible to control character Injection via shell output
Low
CVE-2025-1693
was published
for
mongosh
(npm)
Feb 27, 2025
Matrix IRC Bridge allows IRC command injection to own puppeted user
Low
CVE-2025-27146
was published
for
matrix-appservice-irc
(npm)
Feb 25, 2025
tarteaucitron Cross-site Scripting (XSS)
Low
CVE-2025-1467
was published
for
tarteaucitronjs
(npm)
Feb 23, 2025
smartbanner.js rel noopener vulnerability
Low
CVE-2025-25300
was published
for
smartbanner.js
(npm)
Sep 13, 2019
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Low
CVE-2024-30260
was published
for
undici
(npm)
Apr 4, 2024
AWS Cloud Development Kit (AWS CDK) IAM OIDC custom resource allows connection to unauthorized OIDC provider
Low
CVE-2025-23206
was published
for
aws-cdk-lib
(npm)
Jan 17, 2025
Potential DoS when using ContextLines integration
Low
GHSA-r5w7-f542-q2j4
was published
for
@sentry/astro
(npm)
Jan 28, 2025
Directus has a DOM-Based cross-site scripting (XSS) via layout_options
Low
GHSA-9qrm-48qf-r2rw
was published
for
directus
(npm)
Jan 23, 2025
@sveltejs/kit vulnerable to XSS on dev mode 404 page
Low
CVE-2024-53261
was published
for
@sveltejs/kit
(npm)
Nov 25, 2024
Lodestar snappy checksum issue
Low
GHSA-m9c9-mc2h-9wjw
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
Lodestar snappy decompression issue
Low
GHSA-53rv-hcvm-rpp9
was published
for
@lodestar/reqresp
(npm)
Jan 14, 2025
Prototype pollution in jsii.configureCategories
Low
GHSA-m56h-5xx3-2jc2
was published
for
jsii
(npm)
Dec 18, 2024
Elliptic's verify function omits uniqueness validation
Low
CVE-2024-48949
was published
for
elliptic
(npm)
Oct 10, 2024
Valid ECDSA signatures erroneously rejected in Elliptic
Low
CVE-2024-48948
was published
for
elliptic
(npm)
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API