GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,845
Erlang
36
GitHub Actions
33
Go
2,465
Maven
5,000+
npm
4,088
NuGet
733
pip
3,907
Pub
12
RubyGems
943
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,656 advisories
Filter by severity
xml2rfc has an arbitrary file read vulnerability
High
GHSA-cfmv-h8fx-85m7
was published
for
xml2rfc
(pip)
Aug 26, 2025
traQ Allows Insertion of Sensitive Information into Log File
Moderate
CVE-2025-57813
was published
for
github.com/traPtitech/traQ
(Go)
Aug 26, 2025
ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
High
CVE-2025-57803
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
ImageMagick has a Format String Bug in InterpretImageFilename leads to arbitrary code execution
High
CVE-2025-55298
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
ImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry ":" leads to crash
Low
CVE-2025-55212
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 26, 2025
Easy!Appointments SQL injection vulnerability
Moderate
CVE-2025-50383
was published
for
alextselegidis/easyappointments
(Composer)
Aug 26, 2025
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
High
CVE-2025-5302
was published
for
llama-index-core
(pip)
Aug 26, 2025
request-filtering-agent SSRF Bypass via HTTPS Requests to 127.0.0.1
Moderate
CVE-2025-57814
was published
for
request-filtering-agent
(npm)
Aug 25, 2025
mitmproxy binaries embed a vulnerable python-hyper/h2 dependency
Moderate
GHSA-63cx-g855-hvv4
was published
for
mitmproxy
(pip)
Aug 25, 2025
h2 allows HTTP Request Smuggling due to illegal characters in headers
Moderate
CVE-2025-57804
was published
for
h2
(pip)
Aug 25, 2025
XGrammar affected by Denial of Service by infinite recursion grammars
High
CVE-2025-57809
was published
for
xgrammar
(pip)
Aug 25, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
ImageMagick has Undefined Behavior (function-type-mismatch) in CloneSplayTree
Moderate
CVE-2025-55160
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
imagemagick: integer overflows in MNG magnification
High
CVE-2025-55154
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)
High
CVE-2025-57760
was published
for
langflow
(pip)
Aug 25, 2025
imagemagick: heap-buffer overflow read in MNG magnification with alpha
High
CVE-2025-55004
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick has a heap-buffer-overflow
Low
GHSA-fff3-4rp7-px97
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick has a Memory Leak in magick stream
Low
CVE-2025-53019
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick has a Heap Buffer Overflow in InterpretImageFilename
Low
CVE-2025-53014
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
ImageMagick has a Stack Buffer Overflow in image.c
High
CVE-2025-53101
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Aug 25, 2025
Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions (4.0.16 only)
High
CVE-2025-26467
was published
for
org.apache.cassandra:cassandra-all
(Maven)
Aug 25, 2025
Adminer PHP Object Injection issue leads to Denial of Service
High
CVE-2025-43960
was published
for
vrana/adminer
(Composer)
Aug 25, 2025
PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser
High
CVE-2025-54370
was published
for
phpoffice/phpspreadsheet
(Composer)
Aug 25, 2025
Liferay Portal stored cross-site scripting in text field of the web content structure
Moderate
CVE-2025-43765
was published
for
com.liferay:com.liferay.journal.service
(Maven)
Aug 23, 2025
ProTip!
Advisories are also available from the
GraphQL API