GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,638 advisories
Filter by severity
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
Moderate
CVE-2025-64435
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Moderate
CVE-2025-64434
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
KubeVirt Arbitrary Container File Read
Moderate
CVE-2025-64433
was published
for
github.com/kubevirt/kubevirt
(Go)
Nov 6, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer
Moderate
CVE-2025-64432
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Moderate
CVE-2025-64329
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
Apollo Router Affected by an Access Control Bypass on Polymorphic Types
High
CVE-2025-64173
was published
for
apollo-router
(Rust)
Nov 6, 2025
Apollo Router Improperly Enforces Renamed Access Control Directives
High
CVE-2025-64347
was published
for
apollo-router
(Rust)
Nov 6, 2025
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-52c5-vh7f-26fx
was published
for
prosemirror_to_html
(RubyGems)
Nov 6, 2025
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
Low
GHSA-w2jf-268q-mrvh
was published
for
github.com/opentofu/opentofu
(Go)
Nov 6, 2025
Open redirect endpoint in Datasette
Low
CVE-2025-64481
was published
for
datasette
(pip)
Nov 6, 2025
containerd affected by a local privilege escalation via wide permissions on CRI directory
High
CVE-2024-25621
was published
for
github.com/containerd/containerd
(Go)
Nov 6, 2025
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
High
CVE-2025-64439
was published
for
langgraph-checkpoint
(pip)
Nov 5, 2025
Parse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
High
CVE-2025-64430
was published
for
parse-server
(npm)
Nov 5, 2025
IDOR Vulnerabilities in ZITADEL's Organization API allows Cross-Tenant Data Tempering
High
CVE-2025-64431
was published
for
github.com/zitadel/zitadel
(Go)
Nov 5, 2025
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
Low
CVE-2025-64326
was published
for
weblate
(pip)
Nov 5, 2025
youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects
High
CVE-2025-62596
was published
for
youki
(Rust)
Nov 5, 2025
youki container escape via "masked path" abuse due to mount race conditions
High
CVE-2025-62161
was published
for
youki
(Rust)
Nov 5, 2025
runc container escape and denial of service due to arbitrary write gadgets and procfs write redirects
High
CVE-2025-52881
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
Moderate
CVE-2025-10713
was published
for
org.wso2.carbon.mediation:org.wso2.carbon.localentry
(Maven)
Nov 5, 2025
runc container escape with malicious config due to /dev/console mount and related races
High
CVE-2025-52565
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
runc container escape via "masked path" abuse due to mount race conditions
High
CVE-2025-31133
was published
for
github.com/opencontainers/runc
(Go)
Nov 5, 2025
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
High
CVE-2025-64458
was published
for
django
(pip)
Nov 5, 2025
Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
Critical
CVE-2025-64459
was published
for
django
(pip)
Nov 5, 2025
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Moderate
CVE-2025-58337
was published
for
doris-mcp-server
(pip)
Nov 5, 2025
ProTip!
Advisories are also available from the
GraphQL API