GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,835
Erlang
36
GitHub Actions
33
Go
2,452
Maven
5,000+
npm
4,077
NuGet
723
pip
3,868
Pub
12
RubyGems
943
Rust
1,010
Swift
39
Unreviewed advisories
All unreviewed
5,000+
10,412 advisories
Filter by severity
n8n symlink traversal vulnerability in "Read/Write File" node allows access to restricted files
Moderate
CVE-2025-57749
was published
for
n8n
(npm)
Aug 20, 2025
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
CRI-O has Potential High Memory Consumption from File Read
Moderate
CVE-2025-4437
was published
for
github.com/cri-o/cri-o
(Go)
Aug 20, 2025
Liferay Portal Unvalidated File Upload
Moderate
CVE-2025-43750
was published
for
com.liferay:com.liferay.dynamic.data.mapping.form.web
(Maven)
Aug 20, 2025
Liferay Portal Unauthenticated File Access via URL
Moderate
CVE-2025-43749
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Liferay Portal Vulnerable to Cross-Site Scripting via assetTagNames Parameter
Moderate
CVE-2025-43741
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Liferay Portal Vulnerable to Cross-Site Scripting through URLs
Moderate
CVE-2025-43742
was published
for
com.liferay:com.liferay.layout.type.controller.display.page
(Maven)
Aug 20, 2025
Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
Moderate
CVE-2024-39954
was published
for
org.apache.eventmesh:eventmesh-runtime
(Maven)
Aug 20, 2025
Default Credentials in nginx-defender Configuration Files
Moderate
CVE-2025-55740
was published
for
github.com/Anipaleja/nginx-defender
(Go)
Aug 19, 2025
Liferay Portal Vulnerable to Cross-Site Scripting via DDM Structure Field Labels
Moderate
CVE-2025-43744
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
Liferay Portal Enumeration Discrepancy in Calendars
Moderate
CVE-2025-43743
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
Liferay Portal Vulnerable to Cross-Site Scripting via backURL Paramter
Moderate
CVE-2025-43737
was published
for
com.liferay:com.liferay.journal.web
(Maven)
Aug 19, 2025
Liferay Portal CSRF Vulnerability via Endpoint Parameter
Moderate
CVE-2025-43745
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
WP Crontrol Authenticated (Administrator+) plugin vulnerable to Blind Server-Side Request Forgery
Moderate
CVE-2025-8678
was published
for
johnbillion/wp-crontrol
(Composer)
Aug 19, 2025
Mermaid improperly sanitizes sequence diagram labels leading to XSS
Moderate
CVE-2025-54881
was published
for
mermaid
(npm)
Aug 19, 2025
Mermaid does not properly sanitize architecture diagram iconText leading to XSS
Moderate
CVE-2025-54880
was published
for
mermaid
(npm)
Aug 19, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability in displayType Parameter
Moderate
CVE-2025-43738
was published
for
com.liferay:com.liferay.expando.web
(Maven)
Aug 19, 2025
Astro allows unauthorized third-party images in _image endpoint
Moderate
CVE-2025-55303
was published
for
@astrojs/node
(npm)
Aug 19, 2025
MoonShine Arbitrary File Upload Vulnerability
Moderate
CVE-2025-51489
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
MoonShine SQL Injection Vulnerability
Moderate
CVE-2025-51510
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
moonshine Stored Cross-Site Scripting Vulnerability in Create Article
Moderate
CVE-2025-51487
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
moonshine Stored Cross-Site Scripting Vulnerability in Create Admin
Moderate
CVE-2025-51488
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature
Moderate
CVE-2025-43740
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
Liferay Portal Email Modification Vulnerability via Calendar Portlet
Moderate
CVE-2025-43739
was published
for
com.liferay:com.liferay.calendar.service
(Maven)
Aug 19, 2025
LibreNMS allows stored XSS in Alert Template name field
Moderate
CVE-2025-55296
was published
for
librenms/librenms
(Composer)
Aug 18, 2025
ProTip!
Advisories are also available from the
GraphQL API