GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,477
Maven
5,000+
npm
4,094
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,012
Swift
39
Unreviewed advisories
All unreviewed
5,000+
23,690 advisories
Filter by severity
Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers
Moderate
GHSA-h3qp-7fh3-f8h4
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
Moderate
GHSA-f745-w6jp-hpxx
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression
Moderate
GHSA-f4x7-rfwp-v3xw
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get
Moderate
GHSA-86cj-95qr-2p4f
was published
for
picklescan
(pip)
Aug 22, 2025
Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
Moderate
GHSA-4r9r-ch6f-vxmx
was published
for
picklescan
(pip)
Aug 22, 2025
UnoPim has CSV Injection on Quick Export feature
Low
CVE-2025-55745
was published
for
unopim/unopim
(Composer)
Aug 22, 2025
UnoPim has Broken Access Control
High
CVE-2025-55741
was published
for
unopim/unopim
(Composer)
Aug 22, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
JeecgBoot SQL Injection Vulnerability
Moderate
CVE-2025-51825
was published
for
org.jeecgframework.boot:jeecg-boot-base-core
(Maven)
Aug 22, 2025
Bouncy Castle for Java has Out-of-Bounds Write Vulnerability
Low
CVE-2025-9340
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 22, 2025
Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
Moderate
CVE-2025-9341
was published
for
org.bouncycastle:bc-fips
(Maven)
Aug 22, 2025
Liferay Portal's Unlimited File Upload Could Result in DoS
Moderate
CVE-2025-43752
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 22, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via Form Container
Low
CVE-2025-43753
was published
for
com.liferay:com.liferay.layout.taglib
(Maven)
Aug 22, 2025
hippo4j Includes Hard Coded Secret Key in JWT Creation
High
CVE-2025-51606
was published
for
cn.hippo4j:hippo4j-core
(Maven)
Aug 21, 2025
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
High
CVE-2025-57751
was published
for
pyload-ng
(pip)
Aug 21, 2025
Liferay Portal Username Enumeration Vulnerability
Moderate
CVE-2025-43754
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 21, 2025
Mattermost has Potential Server Crash due to Unvalidated Import Data
Moderate
CVE-2025-8402
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Liferay Portal Stored Cross-Site Scripting Vulnerability via GroupPagesPortlet_type Parameter
Moderate
CVE-2025-43755
was published
for
com.liferay:com.liferay.layout.admin.web
(Maven)
Aug 21, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via snippet Parameter
Moderate
CVE-2025-43756
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 21, 2025
Keycloak Potential Variable Reference in Model Storage Services
Moderate
CVE-2025-9162
was published
for
org.keycloak:keycloak-model-storage-services
(Maven)
Aug 21, 2025
@musistudio/claude-code-router has improper CORS configuration
High
CVE-2025-57755
was published
for
@musistudio/claude-code-router
(npm)
Aug 21, 2025
vite-plugin-static-copy files not included in `src` are possible to access with a crafted request
Moderate
CVE-2025-57753
was published
for
vite-plugin-static-copy
(npm)
Aug 21, 2025
sha.js is missing type checks leading to hash rewind and passing on crafted data
Critical
CVE-2025-9288
was published
for
sha.js
(npm)
Aug 21, 2025
cipher-base is missing type checks, leading to hash rewind and passing on crafted data
Critical
CVE-2025-9287
was published
for
cipher-base
(npm)
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API