GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,791
Maven
5,000+
npm
4,399
NuGet
772
pip
4,175
Pub
12
RubyGems
965
Rust
1,074
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,236 advisories
Filter by severity
AIOHTTP Vulnerable to Cookie Parser Warning Storm
Low
CVE-2025-69230
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP vulnerable to DoS through chunked messages
Moderate
CVE-2025-69229
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP vulnerable to denial of service through large payloads
Moderate
CVE-2025-69228
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP vulnerable to DoS when bypassing asserts
Moderate
CVE-2025-69227
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP vulnerable to brute-force leak of internal static file path components
Low
CVE-2025-69226
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP has unicode match groups in regexes for ASCII protocol elements
Low
CVE-2025-69225
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP's unicode processing of header values could cause parsing discrepancies
Low
CVE-2025-69224
was published
for
aiohttp
(pip)
Jan 5, 2026
AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
High
CVE-2025-69223
was published
for
aiohttp
(pip)
Jan 5, 2026
`vega-functions` vulnerable to Cross-site Scripting via `setdata` function
High
CVE-2025-66648
was published
for
vega-functions
(npm)
Jan 5, 2026
Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope
High
CVE-2025-65110
was published
for
vega-selections
(npm)
Jan 5, 2026
Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
High
CVE-2025-61916
was published
for
io.spinnaker.clouddriver:clouddriver-artifacts
(Maven)
Jan 5, 2026
evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API
Moderate
CVE-2025-67427
was published
for
@evershop/evershop
(npm)
Jan 5, 2026
evershop allows unauthenticated attackers to exhaust application server's resources via "GET /images" API
High
CVE-2025-67419
was published
for
@evershop/evershop
(npm)
Jan 5, 2026
Harvest May Expose OS Default SSH Login Password Via SUSE Virtualization Interactive Installer
Critical
CVE-2025-62877
was published
for
github.com/harvester/harvester-installer
(Go)
Jan 5, 2026
Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read
High
CVE-2026-21857
was published
for
redaxo/source
(Composer)
Jan 5, 2026
ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.
Moderate
GHSA-hqf9-8xv5-x8xw
was published
for
@openzeppelin/confidential-contracts
(npm)
Jan 5, 2026
gix-date can create non-utf8 string with `TimeBuf::as_str`
Moderate
GHSA-6mw6-mj76-grwc
was published
for
gix-date
(Rust)
Jan 5, 2026
Sliver Vulnerable to Pre-Auth Memory Exhaustion via NoEncoder Bypass
Moderate
GHSA-hjr9-wj7v-7hv8
was published
for
github.com/bishopfox/sliver
(Go)
Jan 5, 2026
badkeys vulnerable to ASCII control character injection on console via malformed input
Low
CVE-2026-21439
was published
for
badkeys
(pip)
Jan 5, 2026
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2025-68455
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Unauthenticated Craft CMS users can trigger a database backup
High
CVE-2025-68456
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2025-68454
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
Moderate
CVE-2025-68437
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Moderate
CVE-2025-68436
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
jsPDF has Local File Inclusion/Path Traversal vulnerability
Critical
CVE-2025-68428
was published
for
jspdf
(npm)
Jan 5, 2026
ProTip!
Advisories are also available from the
GraphQL API