GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
21 advisories
Filter by severity
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
Low
CVE-2023-30844
was published
for
github.com/mutagen-io/mutagen
(Go)
May 5, 2023
TYPO3 vulnerable to an HTML Injection in the History Module
Low
CVE-2024-34355
was published
for
typo3/cms-core
(Composer)
May 14, 2024
Fides Webserver Logs Hosted Database Password Partial Exposure Vulnerability
Low
CVE-2024-34715
was published
for
ethyca-fides
(pip)
May 29, 2024
LibreNMS vulnerable to Stored Cross-site Scripting via File Upload
Low
CVE-2024-47528
was published
for
librenms/librenms
(Composer)
Oct 1, 2024
Django TomSelect incomplete escaping of dangerous characters in widget attributes
Low
GHSA-785h-76cm-cpmf
was published
for
django-tomselect
(pip)
Mar 26, 2025
Apache Tomcat Rewrite rule bypass
Low
CVE-2025-31651
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Apr 28, 2025
Umbraco.Forms has HTML injection vulnerability in 'Send email' workflow
Low
CVE-2025-47280
was published
for
Umbraco.Forms
(NuGet)
May 13, 2025
Duplicate Advisory: Multiple issues involving quote API in shlex
Low
GHSA-286m-6pg9-v42v
was published
for
shlex
(Rust)
Jul 28, 2025
•
withdrawn
pretix has Email Content Injection Through Maliciously Formatted Names
Low
CVE-2025-13742
was published
for
pretix
(pip)
Nov 27, 2025
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-xpg8-7m6m-jf56
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
GHSA-2j22-pr5w-6gq8
was published
for
loofah
(RubyGems)
Mar 26, 2026
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Low
CVE-2026-42040
was published
for
axios
(npm)
May 5, 2026
go-git: Improper single-quote escaping in go-git SSH transport
Low
CVE-2026-45570
was published
for
github.com/go-git/go-git
(Go)
May 19, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Low
CVE-2026-46628
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Low
CVE-2026-46637
was published
for
twig/cssinliner-extra
(Composer)
May 21, 2026
OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source
Low
GHSA-9wxg-vf3r-56hc
was published
for
@openzeppelin/wizard
(npm)
Jun 19, 2026
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
Low
CVE-2026-35346
was published
for
uu_comm
(Rust)
Jul 6, 2026
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
Low
GHSA-cwv4-h3j5-w3cf
was published
for
rama
(Rust)
Jul 7, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values
Low
CVE-2026-48598
was published
for
tesla
(Erlang)
Jul 10, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API