GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,300
Maven
5,000+
npm
3,942
NuGet
708
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,526 advisories
Filter by severity
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
High
CVE-2024-12905
was published
for
tar-fs
(npm)
Mar 27, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
nossrf Server-Side Request Forgery (SSRF)
High
CVE-2025-2691
was published
for
nossrf
(npm)
Mar 23, 2025
Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability
High
GHSA-5ccf-884p-4jjq
was published
for
open-webui
(npm)
Mar 20, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High
CVE-2024-12534
was published
for
open-webui
(npm)
Mar 20, 2025
Open WebUI Uncontrolled Resource Consumption vulnerability
High
CVE-2024-12537
was published
for
open-webui
(npm)
Mar 20, 2025
Nuxt allows DOS via cache poisoning with payload rendering response
High
CVE-2025-27415
was published
for
nuxt
(npm)
Mar 19, 2025
jsPDF Bypass Regular Expression Denial of Service (ReDoS)
High
CVE-2025-29907
was published
for
jspdf
(npm)
Mar 18, 2025
In Azle, calling `setTimer` causes infinite loop of timers
High
CVE-2025-29776
was published
for
azle
(npm)
Mar 14, 2025
Prototype Pollution Vulnerability in parse-git-config
High
CVE-2025-25975
was published
for
parse-git-config
(npm)
Mar 12, 2025
Mockoon has a Path Traversal and LFI in the static file serving endpoint
High
GHSA-w7f9-wqc4-3wxr
was published
for
@mockoon/cli
(npm)
Mar 11, 2025
canvg Prototype Pollution vulnerability
High
CVE-2025-25977
was published
for
canvg
(npm)
Mar 10, 2025
Vue I18n Allows Prototype Pollution in `handleFlatJson`
High
CVE-2025-27597
was published
for
@intlify/core
(npm)
Mar 7, 2025
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
High
CVE-2025-27152
was published
for
axios
(npm)
Mar 7, 2025
FlowiseAI Flowise arbitrary file upload vulnerability
High
CVE-2025-26319
was published
for
flowise
(npm)
Mar 5, 2025
mongosh vulnerable to local privilege escalation
High
CVE-2025-1756
was published
for
mongosh
(npm)
Feb 27, 2025
MongoDB Shell may be susceptible to Control Character Injection via autocomplete
High
CVE-2025-1691
was published
for
mongosh
(npm)
Feb 27, 2025
DOM Expressions has a Cross-Site Scripting (XSS) vulnerability due to improper use of string.replace
High
CVE-2025-27108
was published
for
dom-expressions
(npm)
Feb 25, 2025
Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)
High
CVE-2025-27109
was published
for
solid-js
(npm)
Feb 25, 2025
JSONPath Plus allows Remote Code Execution
High
CVE-2025-1302
was published
for
jsonpath-plus
(npm)
Feb 15, 2025
parse-duration has a Regex Denial of Service that results in event loop delay and out of memory
High
CVE-2025-25283
was published
for
parse-duration
(npm)
Feb 12, 2025
Authentication bypass in @sap/approuter
High
CVE-2025-24876
was published
for
@sap/approuter
(npm)
Feb 11, 2025
Unknown vulnerability in Coinbase Wallet SDK
High
GHSA-8rgj-285w-qcq4
was published
for
@coinbase/wallet-sdk
(npm)
Feb 10, 2025
@zag-js/core prototype pollution
High
CVE-2024-57079
was published
for
@zag-js/core
(npm)
Feb 6, 2025
node-opcua-alarm-condition prototype pollution vulnerability
High
CVE-2024-57086
was published
for
node-opcua-alarm-condition
(npm)
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API