GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,308 advisories
Filter by severity
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Moderate
CVE-2025-6037
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Moderate
CVE-2025-6015
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Moderate
CVE-2025-6014
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Moderate
CVE-2025-6004
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Microweber XSS Vulnerability in the homepage Endpoint
Moderate
CVE-2025-51504
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the layout Parameter
Moderate
CVE-2025-51502
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the id Parameter
Moderate
CVE-2025-51501
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Crash due to uncontrolled recursion in protobuf crate
Moderate
CVE-2025-53605
was published
for
protobuf
(Rust)
Mar 7, 2025
Duplicate Advisory: rust-protobuf crate is vulnerable to Uncontrolled Recursion, potentially leading to DoS
Moderate
GHSA-rxf6-323f-44fc
was published
for
protobuf
(Rust)
Jul 5, 2025
•
withdrawn
webfinger.js Blind SSRF Vulnerability
Moderate
CVE-2025-54590
was published
for
webfinger.js
(npm)
Jul 28, 2025
MaterialX Lack of MTLX Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
Moderate
CVE-2025-53012
was published
for
MaterialX
(pip)
Jul 31, 2025
MaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
Moderate
CVE-2025-53009
was published
for
MaterialX
(pip)
Jul 31, 2025
OpenEXR Out-Of-Memory via Unbounded File Header Values
Moderate
CVE-2025-48074
was published
for
OpenEXR
(pip)
Jul 31, 2025
OpenSearch unauthorized data access on fields protected by field level security if field is a member of an object
Moderate
GHSA-2rjv-cv85-xhgm
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
OpenSearch unauthorized data access on fields protected by field masking for fields of type ip, geo_point, geo_shape, xy_point, xy_shape
Moderate
GHSA-rrmm-wq7q-h4v5
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Aug 1, 2025
OpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
Moderate
CVE-2025-48073
was published
for
OpenEXR
(pip)
Jul 31, 2025
OpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
Moderate
CVE-2025-48072
was published
for
OpenEXR
(pip)
Jul 31, 2025
MS SWIFT WEB-UI RCE Vulnerability
Moderate
GHSA-7c78-rm87-5673
was published
for
ms-swift
(pip)
Jul 31, 2025
MS SWIFT Deserialization RCE Vulnerability
Moderate
GHSA-r54c-2xmf-2cf3
was published
for
ms-swift
(pip)
Jul 31, 2025
ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse
Moderate
CVE-2025-4057
was published
for
github.com/arkmq-org/activemq-artemis-operator
(Go)
May 26, 2025
copyparty Reflected XSS via Filter Parameter
Moderate
CVE-2025-54589
was published
for
copyparty
(pip)
Jul 31, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image Plugin
Moderate
CVE-2025-24854
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link Rendering
Moderate
CVE-2025-24853
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Jul 31, 2025
SixLabors ImageSharp Has Infinite Loop in GIF Decoder When Skipping Malformed Comment Extension Blocks
Moderate
CVE-2025-54575
was published
for
SixLabors.ImageSharp
(NuGet)
Jul 30, 2025
Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
Moderate
CVE-2025-54656
was published
for
org.apache.struts:struts-extras
(Maven)
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API