GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,850 advisories
Filter by severity
Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Moderate
CVE-2025-66306
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
fastify-reply-from affected by bypass of reply forwarding
Moderate
CVE-2025-66415
was published
for
@fastify/reply-from
(npm)
Dec 2, 2025
Grav vulnerable to Path Traversal allowing server files backup
Moderate
CVE-2025-66302
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
Moderate
CVE-2025-66307
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL
Critical
CVE-2025-66401
was published
for
mcp-watch
(npm)
Dec 2, 2025
Grav Admin Plugin is vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`
Moderate
CVE-2025-66312
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters
Moderate
CVE-2025-66311
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Exposes Password Hashes Leading to privilege escalation
Moderate
CVE-2025-66304
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to a DOS on the admin panel
Moderate
CVE-2025-66303
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
High
CVE-2025-66301
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to Arbitrary File Read
High
CVE-2025-66300
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)
High
CVE-2025-66299
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
High
CVE-2025-66296
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Keycloak has debug default bind address
Moderate
CVE-2025-11538
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Dec 2, 2025
maxminddb's `Reader::open_mmap` unsoundly marks unsafe memmap operation as safe
Low
GHSA-mj73-j457-8x9q
was published
for
maxminddb
(Rust)
Dec 2, 2025
Werkzeug safe_join() allows Windows special device names
Moderate
CVE-2025-66221
was published
for
werkzeug
(pip)
Dec 2, 2025
rtvm-interpreter lacks sufficient checks in public API
Low
GHSA-pq5v-rwp8-p7gm
was published
for
rtvm-interpreter
(Rust)
Dec 2, 2025
Mattermost fails to validate user permissions when deleting comments in Boards
Moderate
CVE-2025-12756
was published
for
github.com/mattermost/mattermost
(Go)
Dec 1, 2025
Snipe-IT is vulnerable to stored cross-site scripting
Moderate
CVE-2025-65621
was published
for
snipe/snipe-it
(Composer)
Dec 1, 2025
Better Auth affected by external request basePath modification DoS
Low
GHSA-569q-mpph-wgww
was published
for
better-auth
(npm)
Dec 1, 2025
Nodemailer’s addressparser is vulnerable to DoS caused by recursive calls
Low
GHSA-rcmh-qjqh-p98v
was published
for
nodemailer
(npm)
Dec 1, 2025
Spotipy has a XSS vulnerability in its OAuth callback server
Low
CVE-2025-66040
was published
for
spotipy
(pip)
Dec 1, 2025
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
Moderate
CVE-2025-66034
was published
for
fonttools
(pip)
Dec 1, 2025
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Moderate
CVE-2025-64715
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Dec 1, 2025
XWiki Jetty Package (XJetty) allows accessing any application file through URL
High
CVE-2025-55749
was published
for
org.xwiki.platform:xwiki-platform-tool-jetty-resources
(Maven)
Dec 1, 2025
ProTip!
Advisories are also available from the
GraphQL API