GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,835
Erlang
36
GitHub Actions
33
Go
2,452
Maven
5,000+
npm
4,077
NuGet
723
pip
3,868
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
885 advisories
Filter by severity
HashiCorp go-getter Vulnerable to Symlink Attacks
High
CVE-2025-8959
was published
for
github.com/hashicorp/go-getter
(Go)
Aug 15, 2025
External Secrets Operator's Missing Namespace Restriction Allows Unauthorized Secret Access
High
CVE-2025-55196
was published
for
github.com/external-secrets/external-secrets
(Go)
Aug 13, 2025
OliveTin OS Command Injection vulnerability
High
CVE-2025-50946
was published
for
github.com/OliveTin/OliveTin
(Go)
Aug 13, 2025
Komari vulnerable to 2FA Authentication Bypass
High
GHSA-jhmr-57cj-q6g9
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
Komari vulnerable to Cross-site WebSocket Hijacking
High
GHSA-q355-h244-969h
was published
for
github.com/komari-monitor/komari
(Go)
Aug 12, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
High
CVE-2025-52931
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
High
CVE-2025-54525
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-44004
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High
CVE-2025-54996
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Fiber Crashes in BodyParser Due to Unvalidated Large Slice Index in Decoder
High
CVE-2025-54801
was published
for
github.com/gofiber/fiber/v2
(Go)
Aug 5, 2025
RatPanel can perform remote command execution without authorization
High
CVE-2025-53534
was published
for
github.com/tnborg/panel
(Go)
Aug 4, 2025
Hashicorp Vault has Privilege Escalation Vulnerability
High
CVE-2025-5999
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
1Panel agent certificate verification bypass leading to arbitrary command execution
High
CVE-2025-54424
was published
for
github.com/1Panel-dev/1Panel/core
(Go)
Aug 1, 2025
Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Execution
High
CVE-2025-54386
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 1, 2025
eKuiper API endpoints handling SQL queries with user-controlled table names.
High
CVE-2025-54379
was published
for
github.com/lf-edge/ekuiper
(Go)
Jul 24, 2025
Authentik has insufficient check for account active status when authenticating with OAuth/SAML Sources
High
CVE-2025-53942
was published
for
goauthentik.io
(Go)
Jul 22, 2025
Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service
High
CVE-2025-47281
was published
for
github.com/kyverno/kyverno
(Go)
Jul 22, 2025
apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files
High
CVE-2025-53945
was published
for
chainguard.dev/apko
(Go)
Jul 18, 2025
golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability
High
CVE-2025-22868
was published
for
golang.org/x/oauth2
(Go)
Jul 18, 2025
Grafana is vulnerable to XSS attacks through open redirects and path traversal
High
CVE-2025-6023
was published
for
github.com/grafana/grafana
(Go)
Jul 18, 2025
File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing
High
CVE-2025-53893
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 16, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout
High
CVE-2025-53634
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
Chall-Manager's scenario decoding process does not check for zip bombs
High
CVE-2025-53633
was published
for
github.com/ctfer-io/chall-manager
(Go)
Jul 10, 2025
ProTip!
Advisories are also available from the
GraphQL API