GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,889 advisories
Filter by severity
FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management
Moderate
CVE-2025-65657
was published
for
feehi/cms
(Composer)
Dec 2, 2025
assyncmy is vulnerable to SQL injection via crafted dict keys
Critical
CVE-2025-65896
was published
for
asyncmy
(pip)
Dec 2, 2025
GrapesJsBuilder File Upload allows all file uploads
High
CVE-2025-13827
was published
for
mautic/grapes-js-builder-bundle
(Composer)
Dec 2, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
CVE-2025-13828
was published
for
mautic/core
(Composer)
Dec 2, 2025
Apptainer ineffectively applies selinux and apparmor --security options
Moderate
CVE-2025-65105
was published
for
github.com/apptainer/apptainer
(Go)
Dec 2, 2025
Singluarity ineffectively applies selinux / apparmor LSM process labels
Moderate
CVE-2025-64750
was published
for
github.com/sylabs/singularity/v4
(Go)
Dec 2, 2025
Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor
Moderate
CVE-2025-65186
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
Django is vulnerable to DoS via XML serializer text extraction
Moderate
CVE-2025-64460
was published
for
Django
(pip)
Dec 2, 2025
gokey allows secret recovery from a seed file without the master password
High
CVE-2025-13353
was published
for
github.com/cloudflare/gokey
(Go)
Dec 2, 2025
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
Moderate
CVE-2025-66454
was published
for
arcade-mcp-server
(pip)
Dec 2, 2025
vLLM vulnerable to remote code execution via transformers_utils/get_config
High
CVE-2025-66448
was published
for
vllm
(pip)
Dec 2, 2025
Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default
High
CVE-2025-66416
was published
for
mcp
(pip)
Dec 2, 2025
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
High
CVE-2025-66414
was published
for
@modelcontextprotocol/sdk
(npm)
Dec 2, 2025
Calibre-Web Has a Stored Cross-Site Scripting (XSS) Vulnerability via the 'username' Field During User Creation
Low
CVE-2025-65858
was published
for
calibreweb
(pip)
Dec 2, 2025
Mattermost fails to validate user permissions in Boards
Low
CVE-2025-13870
was published
for
github.com/mattermost/mattermost
(Go)
Dec 2, 2025
Eclipse Paho Go MQTT may incorrectly encode strings if length exceeds 65535 bytes
Moderate
CVE-2025-10543
was published
for
github.com/eclipse/paho.mqtt.golang
(Go)
Dec 2, 2025
mdast-util-to-hast has unsanitized class attribute
Moderate
CVE-2025-66400
was published
for
mdast-util-to-hast
(npm)
Dec 2, 2025
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
High
CVE-2025-66298
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
High
CVE-2025-66294
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
Moderate
CVE-2025-66310
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab
Moderate
CVE-2025-66309
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
High
CVE-2025-66297
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`
Moderate
CVE-2025-66308
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
High
CVE-2025-66295
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
ProTip!
Advisories are also available from the
GraphQL API