GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,759
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
773 advisories
Filter by severity
Updatecli exposes Maven credentials in console output
High
CVE-2025-24355
was published
for
github.com/updatecli/updatecli
(Go)
Jan 24, 2025
Envoy Admin Interface Exposed through prometheus metrics endpoint
High
CVE-2025-24030
was published
for
github.com/envoyproxy/gateway
(Go)
Jan 23, 2025
Buildah allows build breakout using malicious Containerfiles and concurrent builds
High
CVE-2024-11218
was published
for
github.com/containers/buildah
(Go)
Jan 21, 2025
HashiCorp go-slug Vulnerable to Zip Slip Attack
High
CVE-2025-0377
was published
for
github.com/hashicorp/go-slug
(Go)
Jan 21, 2025
Insecure default config access in WriteFreely
High
CVE-2025-24337
was published
for
github.com/writefreely/writefreely
(Go)
Jan 20, 2025
Zot IdP group membership revocation ignored
High
CVE-2025-23208
was published
for
zotregistry.dev/zot
(Go)
Jan 17, 2025
Rancher UI has Stored Cross-site Scripting vulnerability
High
CVE-2024-52281
was published
for
github.com/rancher/rancher
(Go)
Jan 14, 2025
Git LFS permits exfiltration of credentials via crafted HTTP URLs
High
CVE-2024-53263
was published
for
github.com/git-lfs/git-lfs
(Go)
Jan 14, 2025
WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover
High
GHSA-2r2v-9pf8-6342
was published
for
github.com/h44z/wg-portal
(Go)
Jan 7, 2025
go-git clients vulnerable to DoS via maliciously crafted Git server replies
High
CVE-2025-21614
was published
for
github.com/go-git/go-git
(Go)
Jan 6, 2025
SiYuan has an arbitrary file deletion vulnerability
High
CVE-2025-21609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jan 3, 2025
Karmada PULL Mode Cluster Privilege Escalation
High
CVE-2024-56513
was published
for
github.com/karmada-io/karmada
(Go)
Jan 3, 2025
OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalation
High
CVE-2024-25133
was published
for
github.com/openshift/hive
(Go)
Dec 31, 2024
Gogs allows argument Injection when tagging new releases
High
CVE-2024-39933
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Navidrome Stores JWT Secret in Plaintext in navidrome.db
High
CVE-2024-56362
was published
for
github.com/navidrome/navidrome
(Go)
Dec 23, 2024
Path Traversal in file update API in gogs
High
CVE-2024-55947
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Remote Command Execution in file editing in gogs
High
CVE-2024-54148
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
GoPhish sends cleartext passwords
High
CVE-2024-55196
was published
for
github.com/gophish/gophish
(Go)
Dec 19, 2024
OpenShift Must Gather Operator Improper Input Validation vulnerability
High
CVE-2024-25131
was published
for
github.com/openshift/must-gather
(Go)
Dec 19, 2024
WhoDB Allows Unbounded Memory Consumption in Authentication Middleware Can Lead to Denial of Service
High
GHSA-5pf6-cq2v-23ww
was published
for
github.com/clidey/whodb/core
(Go)
Dec 19, 2024
Non-linear parsing of case-insensitive content in golang.org/x/net/html
High
CVE-2024-45338
was published
for
golang.org/x/net
(Go)
Dec 18, 2024
Open Cluster Management vulnerable to Trust Boundary Violation
High
CVE-2024-9779
was published
for
open-cluster-management.io/ocm
(Go)
Dec 18, 2024
ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a stack overflow or resource exhaustion
High
GHSA-8wcc-m6j2-qxvm
was published
for
cosmossdk.io/x/tx
(Go)
Dec 16, 2024
MinIO vulnerable to privilege escalation in IAM import API
High
CVE-2024-55949
was published
for
github.com/minio/minio
(Go)
Dec 16, 2024
Potential Vulnerabilities Due to Outdated golang.org/x/crypto Dependency in NanoProxy
High
GHSA-7prj-hgx4-2xc3
was published
for
github.com/ryanbekhen/nanoproxy
(Go)
Dec 12, 2024
ProTip!
Advisories are also available from the
GraphQL API