GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,835 advisories
Filter by severity
YesWiki Cross Site Scripting vulnerability
Moderate
CVE-2025-52277
was published
for
yeswiki/yeswiki
(Composer)
Sep 9, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
Magento Community Edition Improper Input Validation vulnerability
Critical
CVE-2025-54236
was published
for
magento/community-edition
(Composer)
Sep 9, 2025
toodee is vulnerable to Heap Buffer Overflow through its DrainCol Destructor
High
GHSA-pfp7-vxgr-83pw
was published
for
toodee
(Rust)
Sep 9, 2025
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Moderate
CVE-2025-58753
was published
for
copyparty
(pip)
Sep 9, 2025
DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware
High
CVE-2025-59037
was published
for
@duckdb/duckdb-wasm
(npm)
Sep 9, 2025
TYPO3 Workspaces Module Information Disclosure
High
CVE-2025-59018
was published
for
typo3/cms-workspaces
(Composer)
Sep 9, 2025
TYPO3 backend modules have Broken Access Control
Moderate
CVE-2025-59017
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CSV download feature information disclosure
Moderate
CVE-2025-59019
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CMS exposes sensitive information in an error message
Moderate
CVE-2025-59016
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
TYPO3 CMS uses insufficient entropy when generating passwords
Moderate
CVE-2025-59015
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
TYPO3 Bookmark Toolbar vulnerable to denial of service
Moderate
CVE-2025-59014
was published
for
typo3/cms-backend
(Composer)
Sep 9, 2025
TYPO3 CMS has an open‑redirect vulnerability
Moderate
CVE-2025-59013
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through fieldset name in Kaleo Forms Admin
Moderate
CVE-2025-43778
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 9, 2025
Liferay Portal exposes 500 status when attempting login with a deleted client secret
Moderate
CVE-2025-43777
was published
for
com.liferay:com.liferay.portal.security.sso.openid.connect.impl
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through its Style Book theme
Low
CVE-2025-43774
was published
for
com.liferay:com.liferay.frontend.taglib.clay
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to SSRF through custom object attachment fields
Moderate
CVE-2025-43763
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 9, 2025
pREST has a Systemic SQL Injection Vulnerability
Critical
CVE-2025-58450
was published
for
github.com/prest/prest/v2
(Go)
Sep 8, 2025
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
High
CVE-2025-58444
was published
for
@modelcontextprotocol/inspector
(npm)
Sep 8, 2025
XWiki Blog Application: Privilege Escalation (PR) from account through blog content
High
CVE-2025-58365
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Sep 8, 2025
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
High
CVE-2025-57817
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Moderate
CVE-2025-57816
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides has a Lack of Brute-Force Protections on Authentication Endpoints
Low
CVE-2025-57815
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Fides' Admin UI User Password Change Does Not Invalidate Current Session
Low
CVE-2025-57766
was published
for
ethyca-fides
(pip)
Sep 8, 2025
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
ProTip!
Advisories are also available from the
GraphQL API