GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,514
Erlang
33
GitHub Actions
25
Go
2,215
Maven
5,000+
npm
3,873
NuGet
696
pip
3,648
Pub
12
RubyGems
913
Rust
923
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,873 advisories
Filter by severity
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework
High
CVE-2025-31119
was published
for
generator-jhipster-entity-audit
(npm)
Apr 4, 2025
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Critical
CVE-2025-31477
was published
for
@tauri-apps/plugin-shell
(npm)
Apr 2, 2025
Next.js may leak x-middleware-subrequest-id to external hosts
Low
CVE-2025-30218
was published
for
next
(npm)
Apr 2, 2025
image-size Denial of Service via Infinite Loop during Image Processing
High
GHSA-m5qc-5hw7-8vg7
was published
for
image-size
(npm)
Apr 2, 2025
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
High
CVE-2025-31137
was published
for
@react-router/express
(npm)
Apr 1, 2025
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-929m-phjg-qwcc
was published
for
mathlive
(npm)
Apr 1, 2025
•
withdrawn
@alizeait/unflatto Prototype Pollution
High
CVE-2024-38988
was published
for
@alizeait/unflatto
(npm)
Apr 1, 2025
aws-cdk-lib has Insertion of Sensitive Information into Log File vulnerability when using Cognito UserPoolClient Construct
Moderate
GHSA-qq4x-c6h6-rfxh
was published
for
aws-cdk-lib
(npm)
Mar 31, 2025
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
Moderate
CVE-2025-31125
was published
for
vite
(npm)
Mar 31, 2025
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Moderate
GHSA-hx7h-9vf7-5xhg
was published
for
uptime-kuma
(npm)
Mar 31, 2025
Redoc Prototype Pollution via `Module.mergeObjects` Component
High
CVE-2024-57083
was published
for
redoc
(npm)
Mar 28, 2025
Duplicate Advisory: @alizeait/unflatto Prototype Pollution via `exports.unflatto` Method
High
GHSA-799q-f2px-wx8c
was published
for
@alizeait/unflatto
(npm)
Mar 28, 2025
•
withdrawn
depath and cool-path vulnerable to Prototype Pollution via `set()` Method
High
CVE-2024-38985
was published
for
cool-path
(npm)
Mar 28, 2025
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
High
CVE-2024-12905
was published
for
tar-fs
(npm)
Mar 27, 2025
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Moderate
CVE-2025-27793
was published
for
vega
(npm)
Mar 27, 2025
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter
Moderate
CVE-2025-26619
was published
for
vega
(npm)
Mar 27, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
Directus `search` query parameter allows enumeration of non permitted fields
Moderate
CVE-2025-30352
was published
for
directus
(npm)
Mar 26, 2025
Suspended Directus user can continue to use session token to access API
Low
CVE-2025-30351
was published
for
directus
(npm)
Mar 26, 2025
Directus's S3 assets become unavailable after a burst of HEAD requests
Moderate
CVE-2025-30350
was published
for
@directus/storage-driver-s3
(npm)
Mar 26, 2025
Directus's S3 assets become unavailable after a burst of malformed transformations
Moderate
CVE-2025-30225
was published
for
@directus/storage-driver-s3
(npm)
Mar 26, 2025
Shescape has potential environment variable exposure on Windows with CMD
Low
CVE-2025-30222
was published
for
shescape
(npm)
Mar 26, 2025
@mozilla/readability Denial of Service through Regex
Low
CVE-2025-2792
was published
for
@mozilla/readability
(npm)
Mar 26, 2025
ProTip!
Advisories are also available from the
GraphQL API