GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,952
Erlang
39
GitHub Actions
38
Go
2,612
Maven
5,000+
npm
4,252
NuGet
760
pip
4,027
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,467 advisories
Filter by severity
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
High
CVE-2025-64104
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 29, 2025
Zitadel May Bypass Second Authentication Factor
High
CVE-2025-64103
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
Zitadel allows brute-forcing authentication factors
High
CVE-2025-64102
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
ZITADEL Vulnerable to Account Takeover via Malicious Forwarded Header Injection
High
CVE-2025-64101
was published
for
github.com/zitadel/zitadel/v2
(Go)
Oct 29, 2025
OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability
Moderate
GHSA-grjp-54v3-c442
was published
for
usd-core
(pip)
Oct 29, 2025
uv allows ZIP payload obfuscation through parsing differentials
Moderate
GHSA-pqhf-p39g-3x64
was published
for
uv
(pip)
Oct 29, 2025
CKAN vulnerable to fixed session IDs
Moderate
CVE-2025-64100
was published
for
ckan
(pip)
Oct 29, 2025
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
Critical
CVE-2025-64095
was published
for
DNN.PLATFORM
(NuGet)
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
Moderate
CVE-2025-64094
was published
for
DotNetNuke.Core
(NuGet)
Oct 29, 2025
DNN CKEditor Provider allows unauthenticated upload out-of-the-box
Moderate
CVE-2025-62802
was published
for
Dnn.Platform
(NuGet)
Oct 29, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Moderate
CVE-2025-62801
was published
for
fastmcp
(pip)
Oct 29, 2025
FastMCP vulnerable to reflected XSS in client's callback page
Moderate
CVE-2025-62800
was published
for
fastmcp
(pip)
Oct 29, 2025
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
High
GHSA-c2jp-c369-7pvx
was published
for
fastmcp
(pip)
Oct 29, 2025
CKAN vulnerable to stored XSS in resource description
Moderate
CVE-2025-54384
was published
for
ckan
(pip)
Oct 29, 2025
Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
Moderate
CVE-2025-64147
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
Moderate
CVE-2025-64149
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin is missing a permissions check
Moderate
CVE-2025-64150
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Publish to Bitbucket Plugin is missing a permissions check
Moderate
CVE-2025-64148
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
Moderate
CVE-2025-64132
was published
for
io.jenkins.plugins:mcp-server
(Maven)
Oct 29, 2025
Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64133
was published
for
jp.ikedam.jenkins.plugins:extensible-choice-parameter
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin does not mask API tokens displayed on the job configuration form
Moderate
CVE-2025-64145
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files
Moderate
CVE-2025-64144
was published
for
io.jenkins.plugins:byteguard-build-actions
(Maven)
Oct 29, 2025
Jenkins Curseforge Publisher Plugin stores API Keys unencrypted in job config.xml files
Moderate
CVE-2025-64146
was published
for
org.jenkins-ci.plugins:curseforge-publisher
(Maven)
Oct 29, 2025
Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64138
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins OpenShift Pipeline Plugin stores authorization tokens unencrypted in job config.xml files
Moderate
CVE-2025-64143
was published
for
com.openshift.jenkins:openshift-pipeline
(Maven)
Oct 29, 2025
ProTip!
Advisories are also available from the
GraphQL API