GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,308 advisories
Filter by severity
@digitalocean/do-markdownit has Type Confusion vulnerability
Moderate
CVE-2025-59717
was published
for
@digitalocean/do-markdownit
(npm)
Sep 19, 2025
Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages
Moderate
CVE-2025-59417
was published
for
@lobehub/chat
(npm)
Sep 18, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2025-59155
was published
for
hackmd-mcp
(npm)
Sep 15, 2025
Ghost vulnerable to Server Side Request Forgery (SSRF) via oEmbed Bookmark
Moderate
CVE-2025-9862
was published
for
ghost
(npm)
Sep 15, 2025
Stored XSS in n8n LangChain Chat Trigger Node via initialMessages Parameter
Moderate
CVE-2025-58177
was published
for
n8n
(npm)
Sep 15, 2025
MetaMask SDK indirectly exposed via malicious debug@4.4.2 dependency
Moderate
GHSA-qj3p-xc97-xw74
was published
for
@metamask/sdk
(npm)
Sep 15, 2025
express-xss-sanitizer has an unbounded recursion depth
Moderate
CVE-2025-59364
was published
for
express-xss-sanitizer
(npm)
Sep 15, 2025
Hono has Body Limit Middleware Bypass
Moderate
CVE-2025-59139
was published
for
hono
(npm)
Sep 12, 2025
Element Plus Link component (el-link) implements insufficient input validation for the href attribute
Moderate
CVE-2025-57665
was published
for
element-plus
(npm)
Sep 9, 2025
SimStudioAI: A function in route.ts is vulnerable to Code Injection
Moderate
CVE-2025-10097
was published
for
simstudio
(npm)
Sep 8, 2025
sanitize-html is vulnerable to XSS through incomprehensive sanitization
Moderate
CVE-2019-25225
was published
for
sanitize-html
(npm)
Sep 8, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
Moderate
CVE-2025-57752
was published
for
next
(npm)
Aug 29, 2025
Next.js Content Injection Vulnerability for Image Optimization
Moderate
CVE-2025-55173
was published
for
next
(npm)
Aug 29, 2025
Next.js Improper Middleware Redirect Handling Leads to SSRF
Moderate
CVE-2025-57822
was published
for
next
(npm)
Aug 29, 2025
AiondaDotCom mcp-ssh command injection vulnerability in SSH operations
Moderate
CVE-2025-9654
was published
for
@aiondadotcom/mcp-ssh
(npm)
Aug 29, 2025
Payload does not invalidate JWTs after log out
Moderate
CVE-2025-4643
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
Payload's SQLite adapter Session Fixation vulnerability
Moderate
CVE-2025-4644
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
GraphQL Armor Max-Depth Plugin Bypass via fragment caching
Moderate
GHSA-224p-v68g-5g8f
was published
for
@escape.tech/graphql-armor-max-depth
(npm)
Aug 26, 2025
GraphQL Armor Max-Depth Plugin Bypass via Introspection Query Obfuscation
Moderate
GHSA-hmfr-rx46-4jx2
was published
for
@escape.tech/graphql-armor-max-depth
(npm)
Aug 26, 2025
request-filtering-agent SSRF Bypass via HTTPS Requests to 127.0.0.1
Moderate
CVE-2025-57814
was published
for
request-filtering-agent
(npm)
Aug 25, 2025
Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint
Moderate
CVE-2025-43761
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Aug 22, 2025
vite-plugin-static-copy files not included in `src` are possible to access with a crafted request
Moderate
CVE-2025-57753
was published
for
vite-plugin-static-copy
(npm)
Aug 21, 2025
n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted files
Moderate
CVE-2025-57749
was published
for
n8n
(npm)
Aug 20, 2025
ProTip!
Advisories are also available from the
GraphQL API