GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,556
Maven
5,000+
npm
4,228
NuGet
747
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,429 advisories
Filter by severity
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
High
CVE-2025-34267
was published
for
flowise
(npm)
Oct 14, 2025
CometBFT's invalid BitArray handling can lead to network halt
High
GHSA-hrhf-2vcr-ghch
was published
for
github.com/cometbft/cometbft
(Go)
Oct 14, 2025
Argo Workflow may expose artifact repository credentials
High
CVE-2025-62157
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Omni vulnerable to information leak via API
High
CVE-2025-61688
was published
for
github.com/siderolabs/omni
(Go)
Oct 13, 2025
llama-index has Insecure Temporary File
High
CVE-2025-7707
was published
for
llama-index
(pip)
Oct 13, 2025
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
High
CVE-2025-11695
was published
for
mongodb
(Rust)
Oct 13, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
cel-rust May Panic During Parsing of Invalid CEL Expressions
High
CVE-2025-62162
was published
for
cel
(Rust)
Oct 11, 2025
Parallax is vulnerable to DoS via malicious p2p message
High
GHSA-xc79-566c-j4qx
was published
for
github.com/microstack-tech/parallax
(Go)
Oct 10, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
Bagisto is vulnerable to XSS through Admin Panel's product creation path
High
CVE-2025-60880
was published
for
bagisto/bagisto
(Composer)
Oct 10, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
High
CVE-2025-61919
was published
for
rack
(RubyGems)
Oct 10, 2025
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
High
CVE-2025-59530
was published
for
github.com/quic-go/quic-go
(Go)
Oct 10, 2025
Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability
High
CVE-2025-30001
was published
for
org.apache.streampark:streampark
(Maven)
Oct 10, 2025
cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
High
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
Amazon.IonDotnet is vulnerable to Denial of Service attacks
High
CVE-2025-11573
was published
for
Amazon.IonDotnet
(NuGet)
Oct 9, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
Casdoor is vulnerable to Improper Authorization
High
CVE-2025-61524
was published
for
github.com/casdoor/casdoor
(Go)
Oct 8, 2025
FlowiseAI/Flosise has File Upload vulnerability
High
CVE-2025-61687
was published
for
flowise
(npm)
Oct 8, 2025
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
High
CVE-2025-61787
was published
for
deno
(Rust)
Oct 8, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
GHSA-2pgj-5cv2-6xxw
was published
for
fuel-vm
(Rust)
Oct 8, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
High
CVE-2025-6242
was published
for
vllm
(pip)
Oct 7, 2025
ProTip!
Advisories are also available from the
GraphQL API