GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,608
Erlang
33
GitHub Actions
25
Go
2,221
Maven
5,000+
npm
3,893
NuGet
701
pip
3,659
Pub
12
RubyGems
913
Rust
942
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,186 advisories
Filter by severity
CefSharp affected by incorrect handle provided in unspecified circumstances in Mojo on Windows
High
GHSA-f87w-3j5w-v58p
was published
for
CefSharp.OffScreen
(NuGet)
Apr 12, 2025
TigerVNC accessible via the network and not just via a UNIX socket as intended
Critical
CVE-2025-32428
was published
for
jupyter-remote-desktop-proxy
(pip)
Apr 12, 2025
CVE-2025-1386- Query smuggling in ch-go library
Moderate
CVE-2025-1386
was published
for
github.com/ClickHouse/ch-go
(Go)
Apr 12, 2025
Formie has XSS vulnerability for email notification content for preview
Moderate
CVE-2025-32426
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Formie has XSS vulnerability for importing forms
Moderate
CVE-2025-32427
was published
for
verbb/formie
(Composer)
Apr 11, 2025
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
Moderate
GHSA-5q9x-554g-9jgg
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB CPU exhaustion via custom functions result in total DoS
High
GHSA-pxw4-94j3-v9pf
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB no JavaScript script function default timeout could facilitate DoS
Low
GHSA-3824-qmfq-2qv7
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
High
GHSA-3633-g6mg-p6qq
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
Critical
GHSA-ccj3-5p93-8p42
was published
for
surrealdb
(Rust)
Apr 11, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
Moderate
CVE-2025-32027
was published
for
yiisoft/yii
(Composer)
Apr 11, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
Low
GHSA-2cvj-g5r5-jrrg
was published
for
surrealdb
(Rust)
Apr 10, 2025
SurrealDB vulnerable to memory exhaustion via nested functions and scripts
Moderate
GHSA-m7rc-8w7m-r9qr
was published
for
surrealdb
(Rust)
Apr 10, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
High
GHSA-rq86-9m6r-cm3g
was published
for
surrealdb
(Rust)
Apr 10, 2025
Silverstripe Framework user enumeration via timing attack on login and password reset forms
Moderate
GHSA-256q-hx8w-xcqx
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Low
CVE-2025-24866
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 10, 2025
crossbeam-channel Vulnerable to Double Free on Drop
Moderate
GHSA-pg9f-39pc-qf8g
was published
for
crossbeam-channel
(Rust)
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Moderate
CVE-2025-32387
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Silverstripe Framework has a XSS vulnerability in HTML editor
Moderate
CVE-2025-30148
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
Moderate
CVE-2025-25197
was published
for
dnadesign/silverstripe-elemental
(Composer)
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Critical
CVE-2024-58136
was published
for
yiisoft/yii2
(Composer)
Apr 10, 2025
ProTip!
Advisories are also available from the
GraphQL API