GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,207
Maven
5,000+
npm
3,858
NuGet
696
pip
3,639
Pub
12
RubyGems
913
Rust
918
Swift
38
Unreviewed advisories
All unreviewed
5,000+
7,801 advisories
Filter by severity
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
High
CVE-2024-12905
was published
for
tar-fs
(npm)
Mar 27, 2025
Nethermind Juno Potential Denial of Service (DoS) via Integer Overflow
High
CVE-2025-29072
was published
for
github.com/NethermindEth/juno
(Go)
Mar 27, 2025
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
High
CVE-2025-30358
was published
for
mesop
(pip)
Mar 27, 2025
Synapse vulnerable to federation denial of service via malformed events
High
CVE-2025-30355
was published
for
matrix-synapse
(pip)
Mar 27, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
Frappe vulnerable to information disclosure leading to account takeover
High
CVE-2025-30214
was published
for
frappe
(pip)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized mirror annotations
High
CVE-2025-1098
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
High
CVE-2025-24514
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
High
CVE-2025-1097
was published
for
k8s.io/ingress-nginx
(Go)
Mar 25, 2025
OpenDaylight SFC Insecure Shiro Cookie Configuration
High
CVE-2025-29314
was published
for
org.opendaylight.sfc:odl-sfc-openflow-renderer
(Maven)
Mar 24, 2025
OpenDaylight SFC Denial of Service (DoS)
High
CVE-2025-29313
was published
for
org.opendaylight.sfc:odl-sfc-openflow-renderer
(Maven)
Mar 24, 2025
nossrf Server-Side Request Forgery (SSRF)
High
CVE-2025-2691
was published
for
nossrf
(npm)
Mar 23, 2025
Apache Commons VFS Has Relative Path Traversal Vulnerability
High
CVE-2025-27553
was published
for
org.apache.commons:commons-vfs2
(Maven)
Mar 23, 2025
jwt-go allows excessive memory allocation during header parsing
High
CVE-2025-30204
was published
for
github.com/golang-jwt/jwt/v4
(Go)
Mar 21, 2025
PipeCD Vulnerable to Privilege Escalation
High
CVE-2024-53351
was published
for
github.com/pipe-cd/pipecd
(Go)
Mar 21, 2025
Redlib allows a Denial of Service via DEFLATE Decompression Bomb in restore_preferences Form
High
CVE-2025-30160
was published
for
redlib
(Rust)
Mar 21, 2025
Mattermost Fails to Enforce MFA on Plugin Endpoints
High
CVE-2025-25068
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Aim Uncontrolled Resource Consumption vulnerability
High
CVE-2025-0189
was published
for
aim
(pip)
Mar 20, 2025
Aim Excessive Data Query Operations in a Large Data Table vulnerability
High
CVE-2025-0190
was published
for
aim
(pip)
Mar 20, 2025
Ollama Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-0315
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Divide By Zero vulnerability
High
CVE-2025-0317
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
Ollama Denial of Service (DoS) via Null Pointer Dereference
High
CVE-2025-0312
was published
for
github.com/ollama/ollama
(Go)
Mar 20, 2025
LiteLLM Has a Leakage of Langfuse API Keys
High
CVE-2025-0330
was published
for
litellm
(pip)
Mar 20, 2025
LiteLLM Has an Improper Authorization Vulnerability
High
CVE-2025-0628
was published
for
litellm
(pip)
Mar 20, 2025
ZenML unauthenticated DoS via Multipart Boundry
High
CVE-2024-9340
was published
for
zenml
(pip)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API