GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,497 advisories
Filter by severity
Keycloak vulnerable to session takeovers due to reuse of session identifiers
Moderate
CVE-2025-12390
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 28, 2025
ImageMagick has Integer Overflow in BMP Decoder (ReadBMP)
Moderate
CVE-2025-62171
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Oct 28, 2025
Keycloak allows access to admin path through flaw
Low
CVE-2025-10939
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Oct 28, 2025
Liferay Portal Vulnerable to DoS via Crafted Headless API Request
High
CVE-2025-62260
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Liferay Portal Does Not Limit Access to APIs Before Email Verification
Moderate
CVE-2025-62259
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Liferay Portal Vulnerable to CSRF in Headless APIs
High
CVE-2025-62258
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Liferay Portal Stores Password Reset Tokens in Plain Text
Moderate
CVE-2025-62261
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 28, 2025
ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
Moderate
CVE-2025-62594
was published
for
Magick.NET-Q16-HDRI-OpenMP-arm64
(NuGet)
Oct 27, 2025
Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
Moderate
CVE-2025-62262
was published
for
com.liferay:com.liferay.portal.security.ldap.impl
(Maven)
Oct 27, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-62263
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 27, 2025
Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
Moderate
CVE-2025-62253
was published
for
com.liferay:com.liferay.layout.admin.web
(Maven)
Oct 27, 2025
Keycloak TLS Client-Initiated Renegotiation Denial of Service
High
CVE-2025-11419
was published
for
org.keycloak:keycloak-quarkus-dist
(Maven)
Oct 27, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
Wasmtime vulnerable to segfault when using component resources
Low
CVE-2025-62711
was published
for
wasmtime
(Rust)
Oct 27, 2025
BBOT's gitlab.py exposes globally configured "gitlab" API key
Moderate
CVE-2025-10282
was published
for
bbot
(pip)
Oct 27, 2025
InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement
Moderate
CVE-2025-62782
was published
for
de.themoep:inventorygui
(Maven)
Oct 27, 2025
InventoryGui affected by item duplication in GUIs which use GuiStorageElement
Moderate
CVE-2025-62783
was published
for
de.themoep:inventorygui
(Maven)
Oct 27, 2025
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
Low
CVE-2025-61795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Apache Tomcat Vulnerable to Relative Path Traversal
High
CVE-2025-55752
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
Low
CVE-2025-55754
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
pg8000 SQL injection vulnerability via a specially crafted Python list input
High
CVE-2025-61385
was published
for
pg8000
(pip)
Oct 27, 2025
Constellation has insecure LUKS2 persistent storage partitions which may be opened and used
High
CVE-2025-58356
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Oct 27, 2025
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
High
CVE-2025-8709
was published
for
langgraph-checkpoint-sqlite
(pip)
Oct 26, 2025
Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
Moderate
CVE-2025-12194
was published
for
org.bouncycastle:bc-fips
(Maven)
Oct 25, 2025
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Moderate
GHSA-q7jf-gf43-6x6p
was published
for
hono
(npm)
Oct 24, 2025
ProTip!
Advisories are also available from the
GraphQL API