GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
77 advisories
Filter by severity
n8n Has Expression Escape Vulnerability Leading to RCE
Critical
CVE-2026-25049
was published
for
n8n
(npm)
Feb 4, 2026
Crafter CMS has Improper Control of Dynamically-Managed Code Resources
Moderate
CVE-2026-1770
was published
for
org.craftercms:craftercms
(Maven)
Feb 2, 2026
SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
Critical
CVE-2026-23830
was published
for
@nyariv/sandboxjs
(npm)
Jan 27, 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
Critical
CVE-2025-68613
was published
for
n8n
(npm)
Dec 22, 2025
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
Critical
CVE-2025-66398
was published
for
signalk-server
(npm)
Jan 2, 2026
Picklescan does not block ctypes
High
GHSA-4675-36f9-wf6r
was published
for
picklescan
(pip)
Dec 29, 2025
A vulnerability was determined in SamuNatsu HaloBot up to...
Moderate
Unreviewed
CVE-2025-14695
was published
Dec 15, 2025
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to...
High
Unreviewed
CVE-2025-13659
was published
Dec 9, 2025
A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api...
High
Unreviewed
CVE-2025-13426
was published
Dec 6, 2025
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2025-14085
was published
Dec 5, 2025
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById...
Moderate
Unreviewed
CVE-2025-14051
was published
Dec 5, 2025
Improper control of dynamically-managed code resources vulnerability in WebAPI component in...
Moderate
Unreviewed
CVE-2024-5401
was published
Dec 4, 2025
Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring...
Moderate
Unreviewed
CVE-2025-26405
was published
Nov 11, 2025
Rack has a Possible Information Disclosure Vulnerability
Moderate
CVE-2025-61780
was published
for
rack
(RubyGems)
Oct 10, 2025
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
CVE-2025-9905
was published
for
keras
(pip)
Sep 19, 2025
Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
High
GHSA-77wq-646f-jrm2
was published
for
keras
(pip)
Sep 19, 2025
•
withdrawn
An unauthenticated remote attacker can alter the device configuration in a way to get remote code...
Critical
Unreviewed
CVE-2025-25270
was published
Jul 8, 2025
Crafter Studio Groovy Sandbox Bypass
High
CVE-2025-6384
was published
for
org.craftercms:crafter-studio
(Maven)
Jun 19, 2025
A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic...
Low
Unreviewed
CVE-2025-6107
was published
Jun 16, 2025
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Moderate
CVE-2025-31674
was published
for
drupal/core
(Composer)
Apr 1, 2025
In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to...
Low
Unreviewed
CVE-2025-46675
was published
Apr 27, 2025
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use,...
Moderate
Unreviewed
CVE-2025-46673
was published
Apr 27, 2025
GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values...
Moderate
Unreviewed
CVE-2012-2055
was published
May 17, 2022
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by...
High
Unreviewed
CVE-2022-31764
was published
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API