GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
35,026 advisories
Filter by severity
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Critical
CVE-2025-67510
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)
High
CVE-2025-67509
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Filament multi-factor authentication (app) recovery codes can be used multiple times
High
CVE-2025-67507
was published
for
filament/filament
(Composer)
Dec 9, 2025
CNA Plugins Portmap nftables backend can intercept non-local traffic
Moderate
CVE-2025-67499
was published
for
github.com/containernetworking/plugins
(Go)
Dec 9, 2025
SiYuan vulnerable to RCE via zip slip and Command Injection via PandocBin
High
GHSA-4r66-7rcv-x46x
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
SiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
High
CVE-2025-67488
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 9, 2025
HTTP/HTTPS Traffic Interception Bypass in mad-proxy
Moderate
CVE-2025-67485
was published
for
mad-proxy
(pip)
Dec 9, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
High
CVE-2025-66626
was published
for
github.com/argoproj/argo-workflows
(Go)
Dec 9, 2025
Umbraco Vulnerable to Improper File Access and Credential Exposure in Dictionary Import Functionality
Moderate
CVE-2025-66625
was published
for
Umbraco.Cms
(NuGet)
Dec 9, 2025
Elysia affected by arbitrary code injection through cookie config
High
CVE-2025-66457
was published
for
elysia
(npm)
Dec 9, 2025
Elysia vulnerable to prototype pollution with multiple standalone schema validation
Critical
CVE-2025-66456
was published
for
elysia
(npm)
Dec 9, 2025
Open Redirect Vulnerability in Taguette
Moderate
CVE-2025-67502
was published
for
taguette
(pip)
Dec 9, 2025
NiceGUI has a path traversal in app.add_media_files() allows arbitrary file read
High
CVE-2025-66645
was published
for
nicegui
(pip)
Dec 9, 2025
Babylon Incorrect FP inactive accounting in costaking creates “phantom stake” that earns rewards after BTC unbond
Moderate
GHSA-4rmq-mc2c-r495
was published
for
github.com/babylonlabs-io/babylon
(Go)
Dec 9, 2025
Babylon Nil BlockHash in BLS vote extensions triggers panics in consensus handlers
High
GHSA-m6wq-66p2-c8pc
was published
for
github.com/babylonlabs-io/babylon
(Go)
Dec 8, 2025
ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login
High
CVE-2025-67495
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
ZITADEL Vulnerable to Account Takeover Due to Improper Instance Validation in V2 Login
High
CVE-2026-29067
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
ZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login
Critical
CVE-2025-67494
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
Static Web Server vulnerable to a symbolic link path traversal
Moderate
CVE-2025-67487
was published
for
static-web-server
(Rust)
Dec 8, 2025
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Critical
CVE-2025-67489
was published
for
@vitejs/plugin-rsc
(npm)
Dec 8, 2025
Csla affected by Remote Code Execution via WcfProxy (NetDataContractSerializer)
High
CVE-2025-66631
was published
for
Csla
(NuGet)
Dec 8, 2025
Critical Use-After-Free in Wasmi's Linear Memory
High
CVE-2025-66627
was published
for
wasmi
(Rust)
Dec 8, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
CVE-2025-66622
was published
for
matrix-sdk-base
(Rust)
Dec 8, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
ProTip!
Advisories are also available from the
GraphQL API