GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
9,224 advisories
Filter by severity
Django has a potential denial-of-service vulnerability in IPv6 validation
Moderate
CVE-2024-56374
was published
for
Django
(pip)
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
Moderate
CVE-2025-23041
was published
for
Umbraco.Forms
(NuGet)
Jan 14, 2025
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting
Moderate
GHSA-5wjw-h8x5-v65m
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
•
withdrawn
Mediawiki - DataTransfer Extension Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS)
Moderate
CVE-2025-23081
was published
for
mediawiki/data-transfer
(Composer)
Jan 14, 2025
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Moderate
CVE-2024-45627
was published
for
org.apache.linkis:linkis-metadata-query-service-jdbc
(Maven)
Jan 14, 2025
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Indexed Search Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55923
was published
for
typo3/cms-indexed-search
(Composer)
Jan 14, 2025
TYPO3 Form Framework Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55922
was published
for
typo3/cms-form
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Dashboard Module
Moderate
CVE-2024-55920
was published
for
typo3/cms-dashboard
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
TYPO3 Potential Open Redirect via Parsing Differences
Moderate
CVE-2024-55892
was published
for
typo3/cms-core
(Composer)
Jan 14, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2024-56323
was published
for
github.com/openfga/openfga
(Go)
Jan 13, 2025
Denial of Service in Keycloak Server via Security Headers
Moderate
CVE-2024-11734
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
Keycloak allows unrestricted admin use of system and environment variables
Moderate
CVE-2024-11736
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Jan 13, 2025
jte's HTML templates containing Javascript template strings are subject to XSS
Moderate
CVE-2025-23026
was published
for
gg.jte:jte
(Maven)
Jan 13, 2025
notation-go's timestamp signature generation lacks certificate revocation check
Moderate
CVE-2024-56138
was published
for
github.com/notaryproject/notation-go
(Go)
Jan 13, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33299
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33297
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33298
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Drupal Open Social allows Functionality Misuse
Moderate
CVE-2024-13274
was published
for
goalgorilla/open_social
(Composer)
Jan 9, 2025
Mattermost Improper Validation of Specified Type of Input vulnerability
Moderate
CVE-2025-20033
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale
Moderate
CVE-2025-22145
was published
for
nesbot/carbon
(Composer)
Jan 8, 2025
keras Path Traversal vulnerability
Moderate
CVE-2024-55459
was published
for
keras
(pip)
Jan 8, 2025
Soft Serve vulnerable to path traversal attacks
Moderate
CVE-2025-22130
was published
for
github.com/charmbracelet/soft-serve
(Go)
Jan 8, 2025
ProTip!
Advisories are also available from the
GraphQL API