GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,781
Maven
5,000+
npm
4,386
NuGet
772
pip
4,164
Pub
12
RubyGems
965
Rust
1,073
Swift
45
Unreviewed advisories
All unreviewed
5,000+
8,757 advisories
Filter by severity
FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
High
CVE-2025-69210
was published
for
facturascripts/facturascripts
(Composer)
Dec 30, 2025
serverless MCP Server vulnerable to Command Injection in list-projects tool
High
CVE-2025-69256
was published
for
serverless
(npm)
Dec 31, 2025
LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
High
CVE-2025-12183
was published
for
at.yawk.lz4:lz4-java
(Maven)
Nov 28, 2025
PocketMine-MP vulnerable to improperly checked dropped item count leading to server crash
High
CVE-2023-7332
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 6, 2023
Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
High
CVE-2025-68697
was published
for
n8n
(npm)
Dec 26, 2025
Libredesk has Improper Neutralization of HTML Tags in a Web Page
High
CVE-2025-68927
was published
for
github.com/abhinavxd/libredesk
(Go)
Dec 16, 2025
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
High
CVE-2025-15284
was published
for
qs
(npm)
Dec 30, 2025
YOURLS is vulnerable to XSS through JSONP and Callback request parameters
High
GHSA-6mp4-q625-mxjp
was published
for
yourls/yourls
(Composer)
Dec 30, 2025
PsiTransfer has Zip Slip Path Traversal via TAR Archive Download
High
GHSA-xphh-5v4r-r3rx
was published
for
psitransfer
(npm)
Dec 30, 2025
phpMyFAQ has unauthenticated config backup download via /api/setup/backup
High
CVE-2025-69200
was published
for
thorsten/phpmyfaq
(Composer)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
High
GHSA-955r-x9j8-7rhh
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
High
GHSA-46h3-79wf-xr6c
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-rrxm-2pvv-m66x
was published
for
picklescan
(pip)
Dec 30, 2025
Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
High
GHSA-3329-ghmp-jmv5
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
High
GHSA-x843-g5mx-g377
was published
for
picklescan
(pip)
Dec 29, 2025
httparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
High
CVE-2025-68696
was published
for
httparty
(RubyGems)
Dec 23, 2025
Duplicate Advisory: OS Command Injection in Strapi
High
GHSA-49vv-6q7q-w5cf
was published
for
strapi
(npm)
Dec 10, 2021
•
withdrawn
Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
High
GHSA-r8g5-cgf2-4m4m
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan Bypasses Unsafe Globals Check using pty.spawn
High
GHSA-hgrh-qx5j-jfwx
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan missing detection when calling pty.spawn
High
GHSA-vqmv-47xg-9wpr
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan has Incomplete List of Disallowed Inputs
High
GHSA-84r2-jw7c-4r5q
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan does not block ctypes
High
GHSA-4675-36f9-wf6r
was published
for
picklescan
(pip)
Dec 29, 2025
Picklescan vulnerable to Arbitrary File Writing
High
GHSA-m273-6v24-x4m4
was published
for
picklescan
(pip)
Dec 29, 2025
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
ProTip!
Advisories are also available from the
GraphQL API