GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
7,989 advisories
Filter by severity
phpMyAdmin Denial Of Service (DOS) attack
High
CVE-2016-5706
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Duplicate Advisory: Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)
High
GHSA-3hp8-6j24-m5gm
was published
for
camaleon_cms
(RubyGems)
Sep 23, 2024
•
withdrawn
Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'
High
CVE-2023-32194
was published
for
github.com/rancher/rancher
(Go)
Feb 8, 2024
Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)
High
GHSA-7x4w-cj9r-h4v9
was published
for
camaleon_cms
(RubyGems)
Sep 18, 2024
Denial of service in XStream
High
CVE-2017-7957
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jun 30, 2020
XML External Entity Injection in XStream
High
CVE-2016-3674
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Jun 30, 2020
Rancher users who can create Projects can gain access to arbitrary projects
High
CVE-2024-22031
was published
for
github.com/rancher/rancher
(Go)
Apr 25, 2025
Tornado vulnerable to excessive logging caused by malformed multipart form data
High
CVE-2025-47287
was published
for
tornado
(pip)
May 16, 2025
Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability
High
CVE-2025-24070
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2025
Pingora Request Smuggling and Cache Poisoning
High
CVE-2025-4366
was published
for
pingora-core
(Rust)
May 22, 2025
Fiber panics when fiber.Ctx.BodyParser parses invalid range index
High
CVE-2025-48075
was published
for
github.com/gofiber/fiber/v2
(Go)
May 22, 2025
Improper Preservation of Permissions in xxl-job
High
CVE-2024-42681
was published
for
com.xuxueli:xxl-job-core
(Maven)
Aug 15, 2024
Ollama Server Vulnerable to Denial of Service (DoS) Attack
High
CVE-2025-1975
was published
for
github.com/ollama/ollama
(Go)
May 16, 2025
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
High
CVE-2025-4123
was published
for
github.com/grafana/grafana
(Go)
May 22, 2025
Denial of Service in uap-core when processing crafted User-Agent strings
High
GHSA-pcqq-5962-hvcw
was published
for
user_agent_parser
(RubyGems)
Mar 10, 2020
Fluent Fluentd and Fluent-ui use default password
High
CVE-2020-21514
was published
for
fluentd
(RubyGems)
Apr 4, 2023
Babylon Integer Overflow in Distribution Module CumulativeRewardRatio Calculation Leading to Chain Halt
High
GHSA-869w-47c6-fq8q
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
SmallRye Fault Tolerance out-of-memory (OOM) issue
High
CVE-2025-2240
was published
for
io.smallrye:smallrye-fault-tolerance-core
(Maven)
Mar 12, 2025
Multer vulnerable to Denial of Service from maliciously crafted requests
High
CVE-2025-47944
was published
for
multer
(npm)
May 19, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object Reference
High
CVE-2025-48205
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource Location
High
CVE-2025-48201
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
rdiffweb's unlimited length email field can lead to DoS
High
CVE-2022-3272
was published
for
rdiffweb
(pip)
Sep 27, 2022
containerd allows host filesystem access on pull
High
CVE-2025-47290
was published
for
github.com/containerd/containerd/v2
(Go)
May 21, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API