GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,544
Erlang
33
GitHub Actions
25
Go
2,220
Maven
5,000+
npm
3,890
NuGet
700
pip
3,657
Pub
12
RubyGems
913
Rust
942
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,110 advisories
Filter by severity
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
Moderate
GHSA-5q9x-554g-9jgg
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB CPU exhaustion via custom functions result in total DoS
High
GHSA-pxw4-94j3-v9pf
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB no JavaScript script function default timeout could facilitate DoS
Low
GHSA-3824-qmfq-2qv7
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB memory exhaustion via string::replace using regex
High
GHSA-3633-g6mg-p6qq
was published
for
surrealdb
(Rust)
Apr 11, 2025
SurrealDB server-takeover via SurrealQL injection on backup import
Critical
GHSA-ccj3-5p93-8p42
was published
for
surrealdb
(Rust)
Apr 11, 2025
Vite has an `server.fs.deny` bypass with an invalid `request-target`
Moderate
CVE-2025-32395
was published
for
vite
(npm)
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
Moderate
CVE-2025-32027
was published
for
yiisoft/yii
(Composer)
Apr 11, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
Low
GHSA-2cvj-g5r5-jrrg
was published
for
surrealdb
(Rust)
Apr 10, 2025
SurrealDB vulnerable to memory exhaustion via nested functions and scripts
Moderate
GHSA-m7rc-8w7m-r9qr
was published
for
surrealdb
(Rust)
Apr 10, 2025
SurrealDB has uncaught exception in Net module that leads to database crash
High
GHSA-rq86-9m6r-cm3g
was published
for
surrealdb
(Rust)
Apr 10, 2025
Silverstripe Framework user enumeration via timing attack on login and password reset forms
Moderate
GHSA-256q-hx8w-xcqx
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Low
CVE-2025-24866
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 10, 2025
crossbeam-channel Vulnerable to Double Free on Drop
Moderate
GHSA-pg9f-39pc-qf8g
was published
for
crossbeam-channel
(Rust)
Apr 10, 2025
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Moderate
CVE-2025-32387
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Moderate
CVE-2025-32386
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2025
Silverstripe Framework has a XSS vulnerability in HTML editor
Moderate
CVE-2025-30148
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
Moderate
CVE-2025-25197
was published
for
dnadesign/silverstripe-elemental
(Composer)
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Critical
CVE-2024-58136
was published
for
yiisoft/yii2
(Composer)
Apr 10, 2025
Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs
Moderate
CVE-2025-32016
was published
for
Microsoft.Identity.Abstractions
(NuGet)
Apr 9, 2025
Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2025-27391
was published
for
org.apache.activemq:artemis-project
(Maven)
Apr 9, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
wallabag/wallabag Has Multiple Cross-Site Request Forgery (CSRF) Vulnerabilities
Moderate
GHSA-5pm7-cp8f-p2c2
was published
for
wallabag/wallabag
(Composer)
Apr 9, 2025
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
Moderate
CVE-2025-32381
was published
for
xgrammar
(pip)
Apr 9, 2025
ProTip!
Advisories are also available from the
GraphQL API