GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,068 advisories
Filter by severity
Deno vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-21486
was published
for
deno
(Rust)
Jun 5, 2025
Apache IoTDB Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26864
was published
for
org.apache.iotdb:node-commons
(Maven)
May 14, 2025
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Moderate
CVE-2025-26795
was published
for
org.apache.iotdb:iotdb-jdbc
(Maven)
May 14, 2025
OXID eShop May Display User Information
High
CVE-2024-56526
was published
for
oxid-esales/oxideshop-ce
(Composer)
May 13, 2025
Keystone has an unintended `isFilterable` bypass that can be used as an oracle to match hidden fields
Low
CVE-2025-46720
was published
for
@keystone-6/core
(npm)
May 5, 2025
Information Disclosure via Flags override link
Moderate
CVE-2025-46332
was published
for
@vercel/flags
(npm)
May 2, 2025
Moodle allows unauthenticated REST API user data exposure
High
CVE-2025-32044
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle reveals student identities through assignment submissions search on anonymous submissions
Moderate
CVE-2025-3628
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Moderate
CVE-2025-31125
was published
for
vite
(npm)
Mar 31, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
Directus `search` query parameter allows enumeration of non permitted fields
Moderate
CVE-2025-30352
was published
for
directus
(npm)
Mar 26, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
Frappe vulnerable to information disclosure leading to account takeover
High
CVE-2025-30214
was published
for
frappe
(pip)
Mar 25, 2025
Vite bypasses server.fs.deny when using ?raw??
Moderate
CVE-2025-30208
was published
for
vite
(npm)
Mar 25, 2025
Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2025-30474
was published
for
org.apache.commons:commons-vfs2
(Maven)
Mar 23, 2025
Bare Metal Operator (BMO) can expose any secret from other namespaces via BMCEventSubscription CRD
Moderate
CVE-2025-29781
was published
for
github.com/metal3-io/baremetal-operator/apis
(Go)
Mar 17, 2025
Prototype Pollution Vulnerability in parse-git-config
High
CVE-2025-25975
was published
for
parse-git-config
(npm)
Mar 12, 2025
com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
High
CVE-2025-27604
was published
for
com.xwiki.confluencepro:application-confluence-migrator-pro-ui
(Maven)
Mar 7, 2025
URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+
Low
CVE-2025-27221
was published
for
uri
(RubyGems)
Mar 3, 2025
Rancher's SAML-based login via CLI can be denied by unauthenticated users
Moderate
CVE-2025-23387
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
AutoQueryable leaks sensitive information
Moderate
CVE-2024-57716
was published
for
AutoQueryable
(NuGet)
Feb 20, 2025
ProTip!
Advisories are also available from the
GraphQL API