GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,150
Maven
5,000+
npm
3,815
NuGet
690
pip
3,490
Pub
12
RubyGems
902
Rust
900
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,815 advisories
Filter by severity
Prototype Pollution in node-jsonpointer
Moderate
CVE-2021-23807
was published
for
jsonpointer
(npm)
Nov 8, 2021
Prototype pollution in json-pointer
Moderate
CVE-2020-7709
was published
for
json-pointer
(Maven)
May 10, 2021
FlowiseAI Flowise arbitrary file upload vulnerability
High
CVE-2025-26319
was published
for
flowise
(npm)
Mar 5, 2025
Manifest Uses a One-Way Hash without a Salt
Moderate
CVE-2025-27408
was published
for
manifest
(npm)
Mar 3, 2025
seajs Cross-site Scripting vulnerability
Low
CVE-2024-51091
was published
for
seajs
(npm)
Mar 3, 2025
Stage.js DOM Clobbering vulnerabilty
Moderate
CVE-2024-53386
was published
for
stage-js
(npm)
Mar 3, 2025
PrismJS DOM Clobbering vulnerability
Moderate
CVE-2024-53382
was published
for
prismjs
(npm)
Mar 3, 2025
Better Auth allows bypassing the trustedOrigins Protection which leads to ATO
Critical
GHSA-vp58-j275-797x
was published
for
better-auth
(npm)
Feb 24, 2025
Cache variables with the operations when transforms exist on the root level even if variables change in the further requests with the same operation
Moderate
CVE-2025-27097
was published
for
@graphql-mesh/runtime
(npm)
Oct 10, 2023
ejson shell parser in MongoDB Compass maybe bypassed
High
CVE-2024-6376
was published
for
@mongodb-js/connection-form
(npm)
Jul 1, 2024
mongosh vulnerable to local privilege escalation
High
CVE-2025-1756
was published
for
mongosh
(npm)
Feb 27, 2025
MongoDB Shell may be susceptible to control character Injection via shell output
Low
CVE-2025-1693
was published
for
mongosh
(npm)
Feb 27, 2025
MongoDB Shell may be susceptible to control character injection via pasting
Moderate
CVE-2025-1692
was published
for
mongosh
(npm)
Feb 27, 2025
MongoDB Shell may be susceptible to Control Character Injection via autocomplete
High
CVE-2025-1691
was published
for
mongosh
(npm)
Feb 27, 2025
Withdrawn Advisory: marked cross-site scripting vulnerability
Moderate
GHSA-32vw-r77c-gm67
was published
for
marked
(npm)
Aug 3, 2020
•
withdrawn
UNIX Symbolic Link (Symlink) Following in @npmcli/arborist
High
CVE-2021-39135
was published
for
@npmcli/arborist
(npm)
Aug 31, 2021
Matrix IRC Bridge allows IRC command injection to own puppeted user
Low
CVE-2025-27146
was published
for
matrix-appservice-irc
(npm)
Feb 25, 2025
Beter Auth has an Open Redirect via Scheme-Less Callback Parameter
Moderate
CVE-2025-27143
was published
for
better-auth
(npm)
Feb 24, 2025
DOM Expressions has a Cross-Site Scripting (XSS) vulnerability due to improper use of string.replace
High
CVE-2025-27108
was published
for
dom-expressions
(npm)
Feb 25, 2025
Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)
High
CVE-2025-27109
was published
for
solid-js
(npm)
Feb 25, 2025
tarteaucitron Cross-site Scripting (XSS)
Low
CVE-2025-1467
was published
for
tarteaucitronjs
(npm)
Feb 23, 2025
Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
Critical
GHSA-vjh7-7g9h-fjfh
was published
for
elliptic
(npm)
Feb 12, 2025
Cross-site Scripting (XSS) in serialize-javascript
Moderate
CVE-2024-11831
was published
for
serialize-javascript
(npm)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API