GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,086
Maven
5,000+
npm
3,747
NuGet
674
pip
3,436
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
9,189 advisories
Filter by severity
Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation
Moderate
CVE-2024-52594
was published
for
github.com/matrix-org/gomatrixserverlib
(Go)
Jan 16, 2025
Mattermost webapp crash via a crafted post
Moderate
CVE-2025-20621
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 16, 2025
Matrix Media Repo (MMR) allows untrusted file formats can be thumbnailed, invoking potentially further untrusted decoders
Moderate
CVE-2024-56515
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation
Moderate
CVE-2024-52602
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows a denial of service through memory exhaustion
Moderate
CVE-2024-52791
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
HAL Console has a Cross Site Scripting (XSS) vulnerability of user input
Moderate
CVE-2025-23366
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 16, 2025
matrix-media-repo (MMR) allows denial of service/high operating costs through unauthenticated downloads
Moderate
CVE-2024-36403
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content
Moderate
CVE-2024-36402
was published
for
github.com/t2bot/matrix-media-repo
(Go)
Jan 16, 2025
Librenms has a reflected XSS on error alert
Moderate
CVE-2025-23201
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Misc Section Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23200
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Ports Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23199
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23198
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
CVE-2024-5138: snapd snapctl auth bypass
Moderate
CVE-2024-5138
was published
for
github.com/snapcore/snapd
(Go)
Jan 16, 2025
LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability
Moderate
CVE-2024-56144
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
Insecure Temporary File in RESTEasy
Moderate
CVE-2023-0482
was published
for
org.jboss.resteasy:resteasy-core
(Maven)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20086
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost fails to properly validate post props
Moderate
CVE-2025-20088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Mattermost Incorrect Type Conversion or Cast
Moderate
CVE-2025-21088
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 15, 2025
Silverstripe Framework has a XSS in form messages
Moderate
CVE-2024-53277
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS via insert media remote file oembed
Moderate
CVE-2024-47605
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Django has a potential denial-of-service vulnerability in IPv6 validation
Moderate
CVE-2024-56374
was published
for
Django
(pip)
Jan 14, 2025
Umbraco Forms's Short and Long Answer Fields Are Not Validated Server-Side For Maximum Length
Moderate
CVE-2025-23041
was published
for
Umbraco.Forms
(NuGet)
Jan 14, 2025
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting
Moderate
GHSA-5wjw-h8x5-v65m
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
•
withdrawn
Mediawiki - DataTransfer Extension Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS)
Moderate
CVE-2025-23081
was published
for
mediawiki/data-transfer
(Composer)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API