GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,146 advisories
Filter by severity
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
DragonFly's tiny file download uses hard coded HTTP protocol
Moderate
CVE-2025-59410
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly has weak integrity checks for downloaded files
Moderate
CVE-2025-59354
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error
Moderate
CVE-2025-59351
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Dragonfly incorrectly handles a task structure’s usedTrac field
Moderate
CVE-2025-59348
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
NeuVector process with sensitive arguments lead to leakage
Moderate
CVE-2025-54467
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
NeuVector has an insecure password storage vulnerable to rainbow attack
Moderate
CVE-2025-53884
was published
for
github.com/neuvector/neuvector
(Go)
Aug 28, 2025
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header
Moderate
CVE-2025-59342
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
Mattermost makes Use of Weak Hash
Moderate
CVE-2025-9078
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Temporal OSS Server Vulnerable to Allocation of Resources Without Limits or Throttling
Moderate
CVE-2025-8396
was published
for
go.temporal.io/server
(Go)
Sep 15, 2025
Mattermost Missing Authorization vulnerability
Moderate
CVE-2025-9076
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 15, 2025
Moby firewalld reload makes published container ports accessible from remote hosts
Moderate
CVE-2025-54388
was published
for
github.com/docker/docker
(Go)
Jul 29, 2025
github.com/google/nftable IP addresses were encoded in the wrong byte order
Moderate
CVE-2024-6284
was published
for
github.com/google/nftables
(Go)
Jul 4, 2024
secrets-store-sync-controller discloses service account tokens in logs
Moderate
CVE-2025-7445
was published
for
sigs.k8s.io/secrets-store-sync-controller
(Go)
Sep 5, 2025
Memos Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2025-56761
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
Memos Vulnerable to Path Traversal via the CreateResource Endpoint
Moderate
CVE-2025-56760
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
traQ Allows Insertion of Sensitive Information into Log File
Moderate
CVE-2025-57813
was published
for
github.com/traPtitech/traQ
(Go)
Aug 26, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data
Moderate
CVE-2025-8402
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate Remote Cluster Upload Sessions
Moderate
CVE-2025-49222
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API