GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,933
Erlang
39
GitHub Actions
38
Go
2,595
Maven
5,000+
npm
4,247
NuGet
754
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
298,923 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-10727
was published
Oct 23, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2025-10914
was published
Oct 23, 2025
OpenBao and Vault Leak []byte Fields in Audit Logs
Moderate
CVE-2025-62705
was published
for
github.com/openbao/openbao
(Go)
Oct 22, 2025
Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects...
Critical
Unreviewed
CVE-2025-12104
was published
Oct 23, 2025
Client-Side Enforcement of Server-Side Security (CWE-602) in the Command Centre Server allows a...
Moderate
Unreviewed
CVE-2025-41402
was published
Oct 23, 2025
Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the...
Critical
Unreviewed
CVE-2025-47699
was published
Oct 23, 2025
NarSuS App registers a Windows service with an unquoted file path. A user with the write...
High
Unreviewed
CVE-2025-61865
was published
Oct 23, 2025
Movable Type contains a stored cross-site scripting vulnerability in Edit CategorySet of...
Moderate
Unreviewed
CVE-2025-62499
was published
Oct 23, 2025
Exposure of Private Personal Information to an Unauthorized Actor (CWE-359) in the Command Centre...
Moderate
Unreviewed
CVE-2025-35981
was published
Oct 23, 2025
Cleartext Storage of Sensitive Information (CWE-312) in the Gallagher Morpho integration could...
Moderate
Unreviewed
CVE-2025-48428
was published
Oct 23, 2025
Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary...
Moderate
Unreviewed
CVE-2025-62820
was published
Oct 23, 2025
GROWI v4.2.7 and earlier contains a cross-site scripting vulnerability in the page alert...
Moderate
Unreviewed
CVE-2025-54806
was published
Oct 23, 2025
Movable Type contains a stored cross-site scripting vulnerability in Edit ContentData page. If...
Moderate
Unreviewed
CVE-2025-54856
was published
Oct 23, 2025
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly...
Moderate
Unreviewed
CVE-2025-62813
was published
Oct 23, 2025
Uncaught Exception (CWE-248) in the Command Centre Server allows an Authorized and Privileged...
Moderate
Unreviewed
CVE-2025-48430
was published
Oct 23, 2025
Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows...
High
Unreviewed
CVE-2025-11575
was published
Oct 23, 2025
ProTip!
Advisories are also available from the
GraphQL API