GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,617
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,347 advisories
        Filter by severity
        
      
      
    
                    
                      angular vulnerable to regular expression denial of service via the angular.copy() utility
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-26116
                      
                      was published
                        for
                        
                          angular
                        
                        (npm)
                      Mar 30, 2023 
                    
                  
                    
                      angular vulnerable to regular expression denial of service via the $resource service
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-26117
                      
                      was published
                        for
                        
                          angular
                        
                        (npm)
                      Mar 30, 2023 
                    
                  
                    
                      angular vulnerable to regular expression denial of service via the <input type="url"> element
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-26118
                      
                      was published
                        for
                        
                          angular
                        
                        (npm)
                      Mar 30, 2023 
                    
                  
                    
                      angular vulnerable to regular expression denial of service (ReDoS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-25844
                      
                      was published
                        for
                        
                          angular
                        
                        (npm)
                      May 3, 2022 
                    
                  
                    
                      AngularJS Incomplete Filtering of Special Elements vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-2336
                      
                      was published
                        for
                        
                          angular-sanitize
                        
                        (npm)
                      Jun 4, 2025 
                    
                  
                    
                      Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-6485
                      
                      was published
                        for
                        
                          bootstrap
                        
                        (npm)
                      Jul 11, 2024 
                    
                  
                    
                      MongoDB Driver may publish events containing authentication-related data
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32050
                      
                      was published
                        for
                        
                          github.com/mongodb/mongo-swift-driver
                        
                        (Composer)
                      Aug 29, 2023 
                    
                  
                    
                      messageformat prototype pollution vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57353
                      
                      was published
                        for
                        
                          @messageformat/runtime
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      node-tar has a race condition leading to uninitialized memory exposure
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-64118
                      
                      was published
                        for
                        
                          tar
                        
                        (npm)
                      Oct 30, 2025 
                    
                  
                    
                      Parcel has an Origin Validation Error vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-56648
                      
                      was published
                        for
                        
                          @parcel/reporter-dev-server
                        
                        (npm)
                      Sep 17, 2025 
                    
                  
                    
                      NextAuthjs Email misdelivery Vulnerability
                    
                      
  Moderate
                    
                
                      
                        GHSA-5jpx-9hw9-2fx4
                      
                      was published
                        for
                        
                          next-auth
                        
                        (npm)
                      Oct 29, 2025 
                    
                  
                    
                      validator.js has a URL validation bypass vulnerability in its isURL function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-56200
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      rollbar vulnerable to Prototype Pollution in merge()
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62517
                      
                      was published
                        for
                        
                          rollbar
                        
                        (npm)
                      Oct 23, 2025 
                    
                  
                    
                      Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
                    
                      
  Moderate
                    
                
                      
                        GHSA-q7jf-gf43-6x6p
                      
                      was published
                        for
                        
                          hono
                        
                        (npm)
                      Oct 24, 2025 
                    
                  
                    
                      Strapi is vulnerable to Insufficient Session Expiration
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3930
                      
                      was published
                        for
                        
                          @strapi/strapi
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Potential XSS vulnerability in jQuery
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-11023
                      
                      was published
                        for
                        
                          components/jquery
                        
                        (RubyGems)
                      Apr 29, 2020 
                    
                  
                    
                      Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62595
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Oct 21, 2025 
                    
                  
                    
                      vite allows server.fs.deny bypass via backslash on Windows
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62522
                      
                      was published
                        for
                        
                          vite
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
                    
                      
  Moderate
                    
                
                      
                        GHSA-vffh-c9pq-4crh
                      
                      was published
                        for
                        
                          uptime-kuma
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
                    
                      
  Moderate
                    
                
                      
                        GHSA-xvp7-8vm8-xfxx
                      
                      was published
                        for
                        
                          @actual-app/sync-server
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      Mammoth is vulnerable to Directory Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11849
                      
                      was published
                        for
                        
                          Mammoth
                        
                        (Maven)
                      Oct 17, 2025 
                    
                  
                    
                      Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53092
                      
                      was published
                        for
                        
                          @strapi/core
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Strapi Password Hashing Missing Maximum Password Length Validation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-25298
                      
                      was published
                        for
                        
                          @strapi/core
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      CommandKit has incorrect command name exposure in context object for message command aliases
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62378
                      
                      was published
                        for
                        
                          commandkit
                        
                        (npm)
                      Oct 13, 2025 
                    
                  
                    
                      Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62374
                      
                      was published
                        for
                        
                          parse
                        
                        (npm)
                      Oct 14, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API