GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,873
Erlang
37
GitHub Actions
36
Go
2,519
Maven
5,000+
npm
4,156
NuGet
736
pip
3,956
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,948 advisories
Filter by severity
Hugging Face Transformers library has Regular Expression Denial of Service
Moderate
CVE-2025-6051
was published
for
transformers
(pip)
Sep 14, 2025
Liferay Portal's System, Instance and Site Settings are vulnerable to Open Redirect
Moderate
CVE-2025-43795
was published
for
com.liferay:com.liferay.configuration.admin.web
(Maven)
Sep 12, 2025
Liferay Portal: Missing Rate Limiting in GraphQL Endpoint Enables Resource Exhaustion Attack
High
CVE-2025-43796
was published
for
com.liferay:com.liferay.portal.vulcan.api
(Maven)
Sep 12, 2025
Hono has Body Limit Middleware Bypass
Moderate
CVE-2025-59139
was published
for
hono
(npm)
Sep 12, 2025
httpsig-rs: HMAC verification is vulnerable to timing attack
Moderate
CVE-2025-59058
was published
for
httpsig
(Rust)
Sep 12, 2025
Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
Critical
CVE-2025-58434
was published
for
flowise
(npm)
Sep 12, 2025
Liferay Portal's selection modal is vulnerable to XSS
Moderate
CVE-2025-43787
was published
for
com.liferay:com.liferay.users.admin.web
(Maven)
Sep 12, 2025
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Moderate
CVE-2025-6638
was published
for
transformers
(pip)
Sep 12, 2025
Liferay Portal's Organization Selector exposes organization data to remote authenticated users
Moderate
CVE-2025-43788
was published
for
com.liferay:com.liferay.organizations.item.selector.web
(Maven)
Sep 12, 2025
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Low
CVE-2025-43789
was published
for
com.liferay:com.liferay.comment.web
(Maven)
Sep 12, 2025
Neo4j Cypher MCP server is vulnerable to DNS rebinding
High
CVE-2025-10193
was published
for
mcp-neo4j-cypher
(pip)
Sep 11, 2025
SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Moderate
GHSA-7vm2-j586-vcvc
was published
for
SurrealDB
(Rust)
Sep 11, 2025
Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool
Moderate
CVE-2025-56556
was published
for
intelliants/subrion
(Composer)
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
CVE-2025-59047
was published
for
matrix-sdk-base
(Rust)
Sep 11, 2025
Axios is vulnerable to DoS attack through lack of data size check
High
CVE-2025-58754
was published
for
axios
(npm)
Sep 11, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Liferay Portal is vulnerable to Insecure Direct Object Reference (IDOR) attack through Authentication Bypass
High
CVE-2025-43790
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 11, 2025
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Moderate
CVE-2025-58065
was published
for
flask-appbuilder
(pip)
Sep 11, 2025
Prebid-universal-creative latest on npm briefly compromised
Critical
CVE-2025-59039
was published
for
prebid-universal-creative
(npm)
Sep 11, 2025
Prebid.js NPM package briefly compromised
High
CVE-2025-59038
was published
for
prebid.js
(npm)
Sep 11, 2025
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
Low
CVE-2025-9910
was published
for
jsondiffpatch
(npm)
Sep 11, 2025
Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage
High
CVE-2025-59052
was published
for
@angular/platform-server
(npm)
Sep 10, 2025
interactive-git-checkout has a Command Injection vulnerability
Critical
CVE-2025-59046
was published
for
interactive-git-checkout
(npm)
Sep 10, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data
Moderate
CVE-2025-43784
was published
for
com.liferay:com.liferay.headless.builder.impl
(Maven)
Sep 10, 2025
ProTip!
Advisories are also available from the
GraphQL API