GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,948 advisories
Filter by severity
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource
Moderate
CVE-2025-43808
was published
for
com.liferay.commerce:com.liferay.commerce.product.type.virtual.service
(Maven)
Sep 19, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-43809
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 19, 2025
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
CVE-2025-9905
was published
for
keras
(pip)
Sep 19, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
GHSA-w5fx-fh39-j5rw
was published
for
@openai/codex
(npm)
Sep 19, 2025
Grafana-Zabbix ReDoS vulnerability
Moderate
CVE-2025-10630
was published
for
github.com/alexanderzobnin/grafana-zabbix
(Go)
Sep 19, 2025
Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
GHSA-77wq-646f-jrm2
was published
for
keras
(pip)
Sep 19, 2025
•
withdrawn
Keras is vulnerable to Deserialization of Untrusted Data
High
CVE-2025-9906
was published
for
keras
(pip)
Sep 19, 2025
@digitalocean/do-markdownit has Type Confusion vulnerability
Moderate
CVE-2025-59717
was published
for
@digitalocean/do-markdownit
(npm)
Sep 19, 2025
Snipe-IT allows XSS
Moderate
CVE-2025-59712
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
Snipe-IT allows unsafe deserialization
Moderate
CVE-2025-59713
was published
for
snipe/snipe-it
(Composer)
Sep 19, 2025
Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages
Moderate
CVE-2025-59417
was published
for
@lobehub/chat
(npm)
Sep 18, 2025
InvokeAI has External Control of File Name or Path
High
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
@sequa-ai/sequa-mcp has Command Injection vulnerability
Low
CVE-2025-10619
was published
for
@sequa-ai/sequa-mcp
(npm)
Sep 17, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
Pingora update for MadeYouReset HTTP/2 vulnerability
High
GHSA-393w-9x6h-8gc7
was published
for
pingora-core
(Rust)
Sep 17, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
Keycloak SMTP Inject Vulnerability
Moderate
CVE-2025-8419
was published
for
org.keycloak:keycloak-services
(Maven)
Sep 17, 2025
DragonFly's tiny file download uses hard coded HTTP protocol
Moderate
CVE-2025-59410
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly has weak integrity checks for downloaded files
Moderate
CVE-2025-59354
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
High
CVE-2025-59353
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
DragonFly vulnerable to panics due to nil pointer dereference when using variables created alongside an error
Moderate
CVE-2025-59351
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Dragonfly vulnerable to timing attacks against Proxy’s basic authentication
Moderate
CVE-2025-59350
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
ProTip!
Advisories are also available from the
GraphQL API