GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,763 advisories
Filter by severity
pypickle unsafe deserialization vulnerability
Moderate
CVE-2025-5174
was published
for
pypickle
(pip)
May 26, 2025
pypickle Incorrect Privilege Assignment vulnerability
Moderate
CVE-2025-5175
was published
for
pypickle
(pip)
May 26, 2025
HumanSignal label-studio-ml-backend Deserialization of Untrusted Data vulnerability
Moderate
CVE-2025-5173
was published
for
label-studio-ml
(pip)
May 26, 2025
FunAudioLLM InspireMusic deserialization vulnerability
Moderate
CVE-2025-5148
was published
for
inspiremusic
(pip)
May 25, 2025
process_lock has a Potential Unsound issue in unlock
Low
CVE-2025-48751
was published
for
process_lock
(Rust)
May 24, 2025
Process Sync has a Potential Unsound Issue in SharedMutex
Low
CVE-2025-48752
was published
for
process-sync
(Rust)
May 24, 2025
SCSIR has a Potential Unsound Issue in WriteSameCommand
Low
CVE-2025-48756
was published
for
scsir
(Rust)
May 24, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-48371
was published
for
github.com/openfga/openfga
(Go)
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Moderate
CVE-2025-48378
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Moderate
CVE-2025-48377
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
DNN site Import could use an external source with a crafted request
Low
CVE-2025-48376
was published
for
DotNetNuke.SiteExportImport
(NuGet)
May 23, 2025
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Moderate
CVE-2018-25110
was published
for
marked
(npm)
May 23, 2025
Pingora Request Smuggling and Cache Poisoning
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
May 22, 2025
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
High
CVE-2025-48075
was published
for
github.com/gofiber/fiber/v2
(Go)
May 22, 2025
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
High
CVE-2025-4123
was published
for
github.com/grafana/grafana
(Go)
May 22, 2025
Eclipse JGit XML External Entity (XXE) Vulnerability
Moderate
CVE-2025-4949
was published
for
org.eclipse.jgit:org.eclipse.jgit
(Maven)
May 21, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) Remote Code Execution
Critical
CVE-2025-48200
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource Location
High
CVE-2025-48201
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
Ackites KillWxapkg Zip Bomb Resource Exhaustion
Low
CVE-2025-5031
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows XSS
Low
CVE-2025-48206
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object Reference
High
CVE-2025-48205
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows command injections
Moderate
CVE-2025-48204
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
ProTip!
Advisories are also available from the
GraphQL API