GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
8000Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,912
Erlang
39
GitHub Actions
38
Go
2,569
Maven
5,000+
npm
4,245
NuGet
754
pip
4,006
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,289 advisories
Filter by severity
Authlib : JWE zip=DEF decompression bomb enables DoS
Moderate
GHSA-g7f3-828f-7h7m
was published
for
authlib
(pip)
Oct 10, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
python-ldap is Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
Moderate
CVE-2025-61912
was published
for
python-ldap
(pip)
Oct 10, 2025
python-ldap has sanitization bypass in ldap.filter.escape_filter_chars
Moderate
CVE-2025-61911
was published
for
python-ldap
(pip)
Oct 10, 2025
Liferay Portal is vulnerable to CSRF through publication comments
Moderate
CVE-2025-62245
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 10, 2025
Bagisto is vulnerable to XSS through Admin Panel's product creation path
High
CVE-2025-60880
was published
for
bagisto/bagisto
(Composer)
Oct 10, 2025
Sinatra is vulnerable to ReDoS through ETag header value generation
Low
CVE-2025-61921
was published
for
sinatra
(RubyGems)
Oct 10, 2025
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
High
CVE-2025-61920
was published
for
authlib
(pip)
Oct 10, 2025
Rack is vulnerable to a memory-exhaustion DoS through unbounded URL-encoded body parsing
High
CVE-2025-61919
was published
for
rack
(RubyGems)
Oct 10, 2025
Rack has a Possible Information Disclosure Vulnerability
Moderate
CVE-2025-61780
was published
for
rack
(RubyGems)
Oct 10, 2025
quic-go: Panic occurs when queuing undecryptable packets after handshake completion
High
CVE-2025-59530
was published
for
github.com/quic-go/quic-go
(Go)
Oct 10, 2025
Liferay Portal is vulnerable to XSS through its workflow process builder
Moderate
CVE-2025-62239
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Oct 10, 2025
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
Moderate
CVE-2025-60868
was published
for
alt-design/alt-redirect
(Composer)
Oct 10, 2025
Liferay Portal Commerce is vulnerable to XSS through account "name" field
9305
Moderate
CVE-2025-62237
was published
for
com.liferay.commerce:com.liferay.commerce.order.web
(Maven)
Oct 10, 2025
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Moderate
CVE-2025-62238
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 10, 2025
rardecode: DoS risk due to unrestricted RAR dictionary sizes
Moderate
CVE-2025-11579
was published
for
github.com/nwaples/rardecode/v2
(Go)
Oct 10, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Moderate
CVE-2025-37727
was published
for
org.elasticsearch:elasticsearch
(Maven)
Oct 10, 2025
Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability
High
CVE-2025-30001
was published
for
org.apache.streampark:streampark
(Maven)
Oct 10, 2025
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low
CVE-2025-11570
was published
for
drupal-pattern-lab/unified-twig-extensions
(Composer)
Oct 10, 2025
Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
Low
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
•
withdrawn
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical
CVE-2025-10283
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's git_clone.py can expose users' GitHub API keys to an attacker-controlled webserver
Moderate
CVE-2025-10281
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical
CVE-2025-10284
was published
for
bbot
(pip)
Oct 9, 2025
Amazon.IonDotnet is vulnerable to Denial of Service attacks
High
CVE-2025-11573
was published
for
Amazon.IonDotnet
(NuGet)
Oct 9, 2025
Liferay Portal is vulnerable to XSS through its Calendar Events parameters
Moderate
CVE-2025-62240
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Oct 9, 2025
ProTip!
Advisories are also available from the
GraphQL API