GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,766 advisories
Filter by severity
Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in...
Low
Unreviewed
CVE-2025-11934
was published
Nov 22, 2025
With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is...
Low
Unreviewed
CVE-2025-12889
was published
Nov 22, 2025
Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on...
Low
Unreviewed
CVE-2025-11933
was published
Nov 22, 2025
The server previously verified the TLS 1.3 PSK binder using a non-constant time method which...
Low
Unreviewed
CVE-2025-11932
was published
Nov 22, 2025
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit...
Low
Unreviewed
CVE-2025-11931
was published
Nov 22, 2025
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels...
Low
Unreviewed
CVE-2025-12888
was published
Nov 22, 2025
SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
Low
CVE-2025-65111
was published
for
github.com/authzed/spicedb
(Go)
Nov 21, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube...
Low
Unreviewed
CVE-2025-66062
was published
Nov 21, 2025
Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier...
Low
Unreviewed
CVE-2025-52667
was published
Nov 20, 2025
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes...
Low
Unreviewed
CVE-2025-55123
was published
Nov 20, 2025
Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1...
Low
Unreviewed
CVE-2025-52666
was published
Nov 20, 2025
OSV-SCALIBR has NULL Pointer Dereference
Low
CVE-2025-13425
was published
for
github.com/google/osv-scalibr
(Go)
Nov 20, 2025
phppgadmin vulnerable to Cross-site Scripting
Low
CVE-2025-60796
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
Resty has a Path Traversal vulnerability
Low
CVE-2025-13435
was published
for
cn.dreampie:resty
(Maven)
Nov 20, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-11884
was published
Nov 20, 2025
Astro Development Server has Arbitrary Local File Read
Low
CVE-2025-64757
was published
for
astro
(npm)
Nov 19, 2025
HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could...
Low
Unreviewed
CVE-2025-52639
was published
Nov 18, 2025
An Improper Privilege Management vulnerability [CWE-269] in Fortinet FortiOS 7.6.0 through 7.6.3,...
Low
Unreviewed
CVE-2025-54821
was published
Nov 18, 2025
Drupal core allows Content Spoofing
Low
CVE-2025-13082
was published
for
drupal/core
(Composer)
Nov 18, 2025
Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels
Low
CVE-2025-13083
was published
for
drupal/core
(Composer)
Nov 18, 2025
Drupal core allows Forceful Browsing
Low
CVE-2025-13080
was published
for
drupal/core
(Composer)
Nov 18, 2025
Mattermost allows other users to determine when users had read channels via channel member objects
Low
CVE-2025-55074
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 18, 2025
Drupal Simple multi step form allows Cross-Site Scripting
Low
CVE-2025-12761
was published
for
drupal/simple_multistep
(Composer)
Nov 18, 2025
LibreNMS has Weak Password Policy
Low
CVE-2025-65014
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an...
Low
Unreviewed
CVE-2025-64734
was published
Nov 18, 2025
ProTip!
Advisories are also available from the
GraphQL API