GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,966
NuGet
713
pip
3,759
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,861 advisories
Filter by severity
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
Critical
CVE-2025-49596
was published
for
@modelcontextprotocol/inspector
(npm)
Jun 13, 2025
handcraftedinthealps/goodby-csv has Potential Gadget Chain allowing Remote Code Execution
Low
CVE-2025-49597
was published
for
handcraftedinthealps/goodby-csv
(Composer)
Jun 13, 2025
XWiki does not require right warnings for XClass definitions
High
CVE-2025-49585
was published
for
org.xwiki.platform:xwiki-platform-security-requiredrights-default
(Maven)
Jun 13, 2025
XWiki allows remote code execution through preview of XClass changes in AWM editor
High
CVE-2025-49586
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 13, 2025
XWiki does not require right warnings for notification displayer objects
Moderate
CVE-2025-49587
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
XWiki makes title of inaccessible pages available through the class property values REST API
High
CVE-2025-49584
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 13, 2025
XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
Moderate
CVE-2025-49583
was published
for
org.xwiki.platform:xwiki-platform-notifications-notifiers-default
(Maven)
Jun 13, 2025
XWiki allows remote code execution through default value of wiki macro wiki-type parameters
High
CVE-2025-49581
was published
for
org.xwiki.platform:xwiki-platform-rendering-wikimacro-store
(Maven)
Jun 13, 2025
XWiki's required right warnings for macros are incomplete
High
CVE-2025-49582
was published
for
org.xwiki.platform:xwiki-platform-rendering-macro-cache
(Maven)
Jun 13, 2025
XWiki allows privilege escalation through link refactoring
High
CVE-2025-49580
was published
for
org.xwiki.platform:xwiki-platform-refactoring-default
(Maven)
Jun 13, 2025
Solon Vulnerable to Directory Traversal
Moderate
CVE-2025-46096
was published
for
org.noear:solon-faas-luffy
(Maven)
Jun 13, 2025
Ibexa RichText Field Type XSS vulnerabilities in back office
Moderate
GHSA-9qv6-4pwm-m68f
was published
for
ibexa/fieldtype-richtext
(Composer)
Jun 13, 2025
Ibexa Admin UI XSS vulnerabilities in back office
Moderate
GHSA-5r6x-g6jv-4v87
was published
for
ibexa/admin-ui
(Composer)
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Moderate
GHSA-vhgq-r8gx-5fpv
was published
for
ibexa/admin-ui-assets
(Composer)
Jun 13, 2025
Ibexa eZ Platform Admin UI assets XSS vulnerabilities in back office
Moderate
GHSA-r5rx-53g9-25rj
was published
for
ezsystems/ezplatform-admin-ui-assets
(Composer)
Jun 13, 2025
Ibexa eZ Platform Admin UI XSS vulnerabilities in back office
Moderate
GHSA-r7pm-mw8g-p7px
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Jun 13, 2025
starcitizentools/citizen-skin allows stored XSS in user registration date message
Moderate
CVE-2025-49578
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 13, 2025
starcitizentools/citizen-skin allows stored XSS in menu heading message
Moderate
CVE-2025-49579
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 13, 2025
starcitizentools/citizen-skin allows stored XSS in preference menu heading messages
Moderate
CVE-2025-49577
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 13, 2025
starcitizentools/citizen-skin allows stored XSS in search no result messages
Moderate
CVE-2025-49576
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 13, 2025
Salt vulnerable to directory traversal attack in file receiving method
Critical
CVE-2024-38824
was published
for
salt
(pip)
Jun 13, 2025
Salt's worker process vulnerable to denial of service through file read operation
Moderate
CVE-2025-22242
was published
for
salt
(pip)
Jun 13, 2025
Salt's salt.auth.pki module does not properly authenticate callers
Moderate
CVE-2024-38825
was published
for
salt
(pip)
Jun 13, 2025
Salt's file contents overwrite the VirtKey class
Moderate
CVE-2025-22241
was published
for
salt
(pip)
Jun 13, 2025
Salt allows arbitrary directory creation or file deletion
Moderate
CVE-2025-22240
was published
for
salt
(pip)
Jun 13, 2025
ProTip!
Advisories are also available from the
GraphQL API