Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23,948 advisories

Loading
jinjava has Sandbox Bypass via JavaType-Based Deserialization Critical
CVE-2025-59340 was published for com.hubspot.jinjava:jinjava (Maven) Sep 17, 2025
taisehub odgrso
Dragonfly's directories created via os.MkdirAll are not checked for permissions Low
CVE-2025-59349 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly incorrectly handles a task structure’s usedTrac field Moderate
CVE-2025-59348 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication Moderate
CVE-2025-59347 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly vulnerable to server-side request forgery High
CVE-2025-59346 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
Dragonfly doesn't have authentication enabled for some Manager’s endpoints High
CVE-2025-59345 was published for github.com/dragonflyoss/dragonfly (Go) Sep 17, 2025
gaius-qi
esm.sh has arbitrary file write via path traversal in `X-Zone-Id` header Moderate
CVE-2025-59342 was published for github.com/esm-dev/esm.sh (Go) Sep 17, 2025
j3ssie
esm.sh has File Inclusion issue High
CVE-2025-59341 was published for github.com/esm-dev/esm.sh (Go) Sep 17, 2025
j3ssie
REXML has DoS condition when parsing malformed XML file Low
CVE-2025-58767 was published for rexml (RubyGems) Sep 17, 2025
sofiaaberegg
Jenkins has a log message injection vulnerability Moderate
CVE-2025-59476 was published for org.jenkins-ci.main:jenkins-core (Maven) Sep 17, 2025
Jenkins is missing a permission check in the authenticated users' profile menu Moderate
CVE-2025-59475 was published for org.jenkins-ci.main:jenkins-core (Maven) Sep 17, 2025
Jenkins has a missing permission check, allowing users to obtain agent names Moderate
CVE-2025-59474 was published for org.jenkins-ci.main:jenkins-core (Maven) Sep 17, 2025
Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports Critical
GHSA-hf6h-9wq7-hmjg was published for picklescan (pip) Sep 17, 2025 withdrawn
Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check Critical
GHSA-4vr7-g93g-cf6m was published for picklescan (pip) Sep 17, 2025 withdrawn
Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch Critical
GHSA-j424-mc44-f4hj was published for picklescan (pip) Sep 17, 2025 withdrawn
Liferay search widget vulnerable to Cross-site Scripting Moderate
CVE-2025-43804 was published for com.liferay:com.liferay.portal.search (Maven) Sep 17, 2025
Liferay Portal allows remote attackers to view display page templates via crafted URLs Moderate
CVE-2025-43805 was published for com.liferay:com.liferay.asset.display.page.service (Maven) Sep 17, 2025
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain Moderate
CVE-2025-9708 was published for KubernetesClient (NuGet) Sep 17, 2025
Timing Attack Vulnerability in SCRAM Authentication Moderate
GHSA-3wfh-36rx-9537 was published for com.ongres.scram:scram-common (Maven) Sep 16, 2025
jorsol
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another Low
CVE-2025-59160 was published for matrix-js-sdk (npm) Sep 16, 2025
@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode High
CVE-2025-59333 was published for @executeautomation/database-server (npm) Sep 16, 2025
lirantal
Liferay Portal has unchecked input for loop condition vulnerability in XML-RPC Moderate
CVE-2025-43801 was published for com.liferay.portal:com.liferay.portal.impl (Maven) Sep 16, 2025
Spring Expression language property modification using Spring Cloud Gateway Server WebFlux Critical
CVE-2025-41243 was published for org.springframework.cloud:spring-cloud-gateway-server-webflux (Maven) Sep 16, 2025
Podman Creates Temporary File with Insecure Permissions High
CVE-2025-4953 was published for github.com/containers/podman/v5 (Go) Sep 16, 2025
TYPO3 "Form to Database" extension susceptible to Cross-site Scripting Low
CVE-2025-10316 was published for lavitto/typo3-form-to-database (Composer) Sep 16, 2025
ProTip! Advisories are also available from the GraphQL API