GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
971 advisories
Filter by severity
`gh attestation verify` returns incorrect exit code during verification if no attestations are present
Moderate
CVE-2025-25204
was published
for
github.com/cli/cli/v2
(Go)
Feb 14, 2025
Missing rate limit in MaysWind ezBookkeeping
Moderate
CVE-2024-57603
was published
for
github.com/mayswind/ezbookkeeping
(Go)
Feb 13, 2025
Node Denial of Service via kubelet Checkpoint API
Moderate
CVE-2025-0426
was published
for
k8s.io/kubernetes
(Go)
Feb 13, 2025
Apache ServiceComb Service-Center Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2023-44312
was published
for
github.com/apache/servicecomb-service-center
(Go)
Jan 31, 2024
Kube-proxy may unintentionally forward traffic
Moderate
CVE-2021-25736
was published
for
k8s.io/kubernetes
(Go)
Oct 30, 2023
Grafana privilege escalation vulnerability
Moderate
CVE-2023-4822
was published
for
github.com/grafana/grafana
(Go)
Oct 16, 2023
Apache Solr Operator liveness and readiness probes may leak basic auth credentials
Moderate
CVE-2024-31391
was published
for
github.com/apache/solr-operator
(Go)
Apr 12, 2024
Kubernetes mountable secrets policy bypass
Moderate
CVE-2023-2728
was published
for
k8s.io/kubernetes
(Go)
Jul 3, 2023
kube-apiserver vulnerable to policy bypass
Moderate
CVE-2023-2727
was published
for
k8s.io/kubernetes
(Go)
Jul 3, 2023
Apache Answer: XSS vulnerability when changing personal website
Moderate
CVE-2024-29217
was published
for
github.com/apache/incubator-answer
(Go)
Apr 21, 2024
azure-file-csi-driver leaks service account tokens in the logs
Moderate
CVE-2024-3744
was published
for
sigs.k8s.io/azurefile-csi-driver
(Go)
May 15, 2024
secrets-store-csi-driver discloses service account tokens in logs
Moderate
CVE-2023-2878
was published
for
sigs.k8s.io/secrets-store-csi-driver
(Go)
May 26, 2023
Duplicate Advisory: Grafana Improper Access Control vulnerability
Moderate
GHSA-wm7r-3qxj-5xgq
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
•
withdrawn
Duplicate Advisory: Grafana Stored Cross-site Scripting vulnerability
Moderate
GHSA-3cgw-hfw7-wc7j
was published
for
github.com/grafana/grafana
(Go)
Mar 23, 2023
•
withdrawn
Grafana vulnerable to Cross-site Scripting
Moderate
CVE-2023-0507
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain
Moderate
GHSA-6fgm-x6ff-w78f
was published
for
github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7
(Go)
Feb 12, 2025
1Panel open source panel project has an unauthorized vulnerability.
Moderate
CVE-2024-27288
was published
for
github.com/1Panel-dev/1Panel
(Go)
Mar 6, 2024
Helm shows secrets in clear text
Moderate
CVE-2019-25210
was published
for
helm.sh/helm/v3
(Go)
Mar 3, 2024
CRI-O Path Traversal vulnerability
Moderate
CVE-2025-0750
was published
for
github.com/cri-o/cri-o
(Go)
Jan 28, 2025
Juju controller - Arbitrary file reading vulnerability
Moderate
CVE-2023-0092
was published
for
github.com/juju/juju
(Go)
Mar 1, 2023
1Panel arbitrary file write vulnerability
Moderate
CVE-2024-34352
was published
for
github.com/1Panel-dev/1Panel
(Go)
May 9, 2024
Plenti - Code Injection - Denial of Services
Moderate
GHSA-mj4v-hp69-27x5
was published
for
github.com/plentico/plenti
(Go)
Feb 5, 2025
wasmvm: Malicious smart contract can slow down block production
Moderate
GHSA-mx2j-7cmv-353c
was published
for
cosmwasm-vm
(Go)
Feb 4, 2025
wasmvm: Malicious smart contract can crash the chain
Moderate
GHSA-23qp-3c2m-xx6w
was published
for
github.com/CosmWasm/wasmvm
(Go)
Feb 4, 2025
Withdrawn Advisory: github.com/hashicorp/yamux's DefaultConfig has dangerous defaults causing hung Read
Moderate
GHSA-29qp-crvh-w22m
was published
for
github.com/hashicorp/yamux
(Go)
Jan 29, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API