GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,803
Erlang
36
GitHub Actions
29
Go
2,387
Maven
5,000+
npm
4,019
NuGet
720
pip
3,812
Pub
12
RubyGems
930
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,212 advisories
Filter by severity
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
Moderate
CVE-2025-53652
was published
for
org.jenkins-ci.tools:git-parameter
(Maven)
Jul 9, 2025
Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
Moderate
CVE-2025-53650
was published
for
org.jenkins-ci.plugins:credentials-binding
(Maven)
Jul 9, 2025
Qwik's unhandled exception vulnerabilty can cause server crashes from malicious requests
Critical
CVE-2025-53620
was published
for
@builder.io/qwik-city
(npm)
Jul 9, 2025
@clerk/backend Performs Insufficient Verification of Data Authenticity
High
CVE-2025-53548
was published
for
@clerk/astro
(npm)
Jul 9, 2025
Contrast vulnerability allows arbitrary host data Injection into container VOLUME mount points
Low
GHSA-phhq-63jg-fp7r
was published
for
github.com/edgelesssys/contrast
(Go)
Jul 9, 2025
Juju allows arbitrary executable uploads via authenticated endpoint without authorization
High
CVE-2025-0928
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Juju vulnerable to sensitive log retrieval via authenticated endpoint without authorization
Moderate
CVE-2025-53512
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
mcp-remote exposed to OS command injection via untrusted MCP server connections
Critical
CVE-2025-6514
was published
for
mcp-remote
(npm)
Jul 9, 2025
Juju zip slip vulnerability via authenticated endpoint
High
CVE-2025-53513
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Cosmos SDK's Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt
High
GHSA-p22h-3m2v-cmgh
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jul 8, 2025
Helm vulnerable to Code Injection through malicious chart.yaml content
High
CVE-2025-53547
was published
for
helm.sh/helm/v3
(Go)
Jul 8, 2025
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
High
CVE-2025-7346
was published
for
pyload-ng
(pip)
Jul 8, 2025
MCP Server Kubernetes vulnerable to command injection in several tools
High
CVE-2025-53355
was published
for
mcp-server-kubernetes
(npm)
Jul 8, 2025
Babylon vulnerable to chain halt when a message modifies the validator set at the epoch boundary
High
GHSA-rj53-j6jw-7f7g
was published
for
github.com/babylonlabs-io/babylon/v2
(Go)
Jul 8, 2025
Cloudflare Vite plugin exposes secrets over the built-in dev server
Moderate
GHSA-4pfg-2mw5-f8jx
was published
for
@cloudflare/vite-plugin
(npm)
Jul 8, 2025
Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection
High
CVE-2025-53372
was published
for
node-code-sandbox-mcp
(npm)
Jul 8, 2025
Duplicate Advisory: GHSA-x698-5hjm-w2m5
High
GHSA-2wcm-vx67-3x4q
was published
for
pyload-ng
(pip)
Jul 8, 2025
•
withdrawn
fastapi-guard is vulnerable to ReDoS through inefficient regex
Moderate
CVE-2025-53539
was published
for
fastapi-guard
(pip)
Jul 7, 2025
Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes
Low
CVE-2025-53535
was published
for
better-auth
(npm)
Jul 7, 2025
Dagster vulnerable to Path Traversal attack through its /logs endpoint
Moderate
CVE-2023-51232
was published
for
dagster
(pip)
Jul 7, 2025
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
High
CVE-2025-6209
was published
for
llama-index-core
(pip)
Jul 7, 2025
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Moderate
CVE-2025-5472
was published
for
llama-index-core
(pip)
Jul 7, 2025
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
Moderate
CVE-2025-6210
was published
for
llama-index-readers-obsidian
(pip)
Jul 7, 2025
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
High
CVE-2025-6386
was published
for
lollms
(pip)
Jul 7, 2025
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Moderate
CVE-2025-3262
was published
for
transformers
(pip)
Jul 7, 2025
ProTip!
Advisories are also available from the
GraphQL API