GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,766
Maven
5,000+
npm
4,371
NuGet
767
pip
4,144
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,113 advisories
Filter by severity
Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplification
High
GHSA-83jg-m2pm-4jxj
was published
for
cowrie
(pip)
Dec 20, 2025
External Control of File Name or Path in Langflow
High
CVE-2025-68478
was published
for
langflow
(pip)
Dec 19, 2025
Langflow vulnerable to Server-Side Request Forgery
High
CVE-2025-68477
was published
for
langflow
(pip)
Dec 19, 2025
Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature
Low
GHSA-24v3-254g-jv85
was published
for
@tutao/tutanota-utils
(npm)
Dec 19, 2025
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
Moderate
CVE-2025-13467
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Dec 19, 2025
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
Moderate
CVE-2025-68481
was published
for
fastapi-users
(pip)
Dec 19, 2025
Orejime has executable code in HTML attributes
Low
CVE-2025-68457
was published
for
orejime
(npm)
Dec 19, 2025
pretix has Broken Access Control Allowing Cross-User File Access via UUID
Low
CVE-2025-14881
was published
for
pretix
(pip)
Dec 19, 2025
pretix has Broken Access Control Allowing Cross-User File Access via UUID
Low
CVE-2025-14882
was published
for
pretix
(pip)
Dec 19, 2025
Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
High
CVE-2025-66524
was published
for
org.apache.nifi:nifi-asana-processors
(Maven)
Dec 19, 2025
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
Moderate
CVE-2025-14546
was published
for
fastapi-sso
(pip)
Dec 19, 2025
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
Moderate
CVE-2025-68384
was published
for
org.elasticsearch.plugin:x-pack-security
(Maven)
Dec 19, 2025
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
Moderate
CVE-2025-68383
was published
for
github.com/elastic/beats
(Go)
Dec 19, 2025
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
Moderate
CVE-2025-68390
was published
for
org.elasticsearch.plugin:x-pack-core
(Maven)
Dec 19, 2025
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments
High
CVE-2025-68388
was published
for
github.com/elastic/beats
(Go)
Dec 19, 2025
Weblate is vulnerable to RCE through Git config file overwrite
Critical
CVE-2025-68398
was published
for
Weblate
(pip)
Dec 18, 2025
Weblate has an arbitrary file read via symbolic links
High
CVE-2025-68279
was published
for
Weblate
(pip)
Dec 18, 2025
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
High
CVE-2025-53000
was published
for
nbconvert
(pip)
Dec 18, 2025
Apache Log4j does not verify the TLS hostname in its Socket Appender
Moderate
CVE-2025-68161
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 18, 2025
AWS SDK for PHP's S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14761
was published
for
aws/aws-sdk-php
(Composer)
Dec 18, 2025
AWS SDK for Ruby's S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14762
was published
for
aws-sdk-s3
(RubyGems)
Dec 18, 2025
Amazon S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14764
was published
for
github.com/aws/amazon-s3-encryption-client-go/v3
(Go)
Dec 18, 2025
Storybook manager bundle may expose environment variables during build
High
CVE-2025-68429
was published
for
storybook
(npm)
Dec 18, 2025
tinacms is vulnerable to arbitrary code execution
High
CVE-2025-68278
was published
for
@tinacms/cli
(npm)
Dec 18, 2025
Ollama Platform has missing authentication enabling attackers to perform model management operations
Critical
CVE-2025-63389
was published
for
github.com/ollama/ollama
(Go)
Dec 18, 2025
ProTip!
Advisories are also available from the
GraphQL API