Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,949 advisories

Loading
image-size Denial of Service via Infinite Loop during Image Processing High
GHSA-m5qc-5hw7-8vg7 was published for image-size (npm) Apr 2, 2025
dellalibera TheFrankemon
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers High
CVE-2025-31137 was published for @react-router/express (npm) Apr 1, 2025
cold-try
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS Moderate
GHSA-929m-phjg-qwcc was published for mathlive (npm) Apr 1, 2025 withdrawn
@alizeait/unflatto Prototype Pollution High
CVE-2024-38988 was published for @alizeait/unflatto (npm) Apr 1, 2025
gifplayer XSS vulnerability Moderate
CVE-2025-31128 was published for gifplayer (npm) Mar 31, 2025
Rudloff
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query Moderate
CVE-2025-31125 was published for vite (npm) Mar 31, 2025
Iuhsssss
Redoc Prototype Pollution via `Module.mergeObjects` Component High
CVE-2024-57083 was published for redoc (npm) Mar 28, 2025
Duplicate Advisory: @alizeait/unflatto Prototype Pollution via `exports.unflatto` Method High
GHSA-799q-f2px-wx8c was published for @alizeait/unflatto (npm) Mar 28, 2025 withdrawn
alizeait
depath and cool-path vulnerable to Prototype Pollution via `set()` Method High
CVE-2024-38985 was published for cool-path (npm) Mar 28, 2025
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File High
CVE-2024-12905 was published for tar-fs (npm) Mar 27, 2025
pcreager23
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace] Moderate
CVE-2025-27793 was published for vega (npm) Mar 27, 2025
FallingPineapples hydrosquall
domoritz
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter Moderate
CVE-2025-26619 was published for vega (npm) Mar 27, 2025
kprevas hydrosquall
domoritz mattijn lsh
Directus's webhook trigger flows can leak sensitive data High
CVE-2025-30353 was published for directus (npm) Mar 26, 2025
dzevs
Directus `search` query parameter allows enumeration of non permitted fields Moderate
CVE-2025-30352 was published for directus (npm) Mar 26, 2025
hanneskuettner moritzgvt
Suspended Directus user can continue to use session token to access API Low
CVE-2025-30351 was published for directus (npm) Mar 26, 2025
Directus's S3 assets become unavailable after a burst of HEAD requests Moderate
CVE-2025-30350 was published for @directus/storage-driver-s3 (npm) Mar 26, 2025
joselcvarela
Directus's S3 assets become unavailable after a burst of malformed transformations Moderate
CVE-2025-30225 was published for @directus/storage-driver-s3 (npm) Mar 26, 2025
joselcvarela
Shescape has potential environment variable exposure on Windows with CMD Low
CVE-2025-30222 was published for shescape (npm) Mar 26, 2025
@mozilla/readability Denial of Service through Regex Low
CVE-2025-2792 was published for @mozilla/readability (npm) Mar 26, 2025
Vite bypasses server.fs.deny when using ?raw?? Moderate
CVE-2025-30208 was published for vite (npm) Mar 25, 2025
Ezzer17
AWS CDK CodePipeline: trusted entities are too broad Low
GHSA-5pq3-h73f-66hr was published for aws-cdk-lib (npm) Mar 24, 2025
GetmeUK ContentTools Cross-Site Scripting (XSS) Moderate
CVE-2025-2699 was published for ContentTools (npm) Mar 24, 2025
nossrf Server-Side Request Forgery (SSRF) High
CVE-2025-2691 was published for nossrf (npm) Mar 23, 2025
ProTip! Advisories are also available from the GraphQL API