Browse Security Advisories
Security Advisories from github Clear Filters
Critical
about 3 hours ago
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
rubygems
activestorage
Low
about 4 hours ago
MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
rubygems
msgpack
High
about 6 hours ago
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
pypi
flyto-core
High
about 6 hours ago
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
pypi
flyto-core
Critical
about 6 hours ago
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
pypi
flyto-core
High
about 6 hours ago
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
pypi
flyto-core
High
about 6 hours ago
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
pypi
flyto-core
Critical
about 6 hours ago
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
pypi
flyto-core
Moderate
about 6 hours ago
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
pypi
linuxfabrik-lib
High
about 6 hours ago
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
rubygems
mcp
Moderate
about 6 hours ago
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
rubygems
mcp
Moderate
about 6 hours ago
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
rubygems
mcp
Moderate
about 6 hours ago
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
rubygems
mcp
Moderate
about 6 hours ago
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
go
github.com/OliveTin/OliveTin
Moderate
about 7 hours ago
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
go
github.com/OliveTin/OliveTin
High
about 7 hours ago
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
go
github.com/OliveTin/OliveTin
Moderate
1 day ago
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
maven
io.opentelemetry.javaagent:opentelemetry-javaagent
Moderate
1 day ago
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
maven
io.opentelemetry.javaagent:opentelemetry-javaagent
Low
1 day ago
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
rubygems
activerecord-tenanted
High
1 day ago
netfoil: Incorrect block responses could lead to localhost traffic
go
github.com/tinfoil-factory/netfoil
Critical
1 day ago
Logging operator has Fluentd configuration injection that allows remote code execution
go
github.com/kube-logging/logging-operator
High
1 day ago
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
pypi
proot-distro
High
1 day ago
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
pypi
proot-distro
Low
1 day ago
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
packagist
alextselegidis/easyappointments
Low
1 day ago
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
packagist
alextselegidis/easyappointments
Moderate
1 day ago
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
packagist
alextselegidis/easyappointments
Low
1 day ago
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
packagist
alextselegidis/easyappointments
Low
1 day ago
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
packagist
alextselegidis/easyappointments
High
1 day ago
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
packagist
alextselegidis/easyappointments
Moderate
1 day ago
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
pypi
matrix-commander
High
1 day ago
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
npm
@aws/agentcore
Critical
1 day ago
prebid-server's request forgery vulnerability allows for possible host environment data extraction
go
github.com/prebid/prebid-server, github.com/prebid/prebid-server/v2, github.com/prebid/prebid-server/v3, github.com/prebid/prebid-server/v4
High
1 day ago
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
maven
io.quarkus:quarkus-vertx-http
Low
1 day ago
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
npm
@dynatrace-oss/dynatrace-mcp-server
Moderate
1 day ago
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
pypi
penelope-shell-handler
Moderate
1 day ago
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
hex
req
Moderate
1 day ago
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
maven
org.verapdf:validation-model-jakarta, org.verapdf:validation-model
High
1 day ago
veraPDF Validation XXE via Rich Text
maven
org.verapdf:validation-model-jakarta, org.verapdf:validation-model
High
1 day ago
veraPDF Validation XXE via XFA
maven
org.verapdf:validation-model-jakarta, org.verapdf:validation-model
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped enum string values
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
npm
swagger-typescript-api
Moderate
1 day ago
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
npm
swagger-typescript-api
High
1 day ago
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
npm
swagger-typescript-api
Moderate
2 days ago
goshs has ACL Bypass & Path Traversal
go
goshs.de/goshs, github.com/patrickhener/goshs, goshs.de/goshs/v2, github.com/patrickhener/goshs/v2
Moderate
2 days ago
Pagy I18n locale option is not validated before being used in a file path
rubygems
pagy
Moderate
2 days ago
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
cargo
skilo
High
2 days ago
Style Dictionary - Prototype Pollution in convertTokenData utility function
npm
style-dictionary
High
2 days ago
openhole-server vulnerable to path traversal via URL-decoded request path
go
github.com/bablilayoub/openhole
Critical
2 days ago
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
npm
@hypequery/clickhouse
High
2 days ago
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
go
github.com/gotd/td
Moderate
2 days ago
goshs has a Path Traversal issue
go
github.com/patrickhener/goshs/v2, goshs.de/goshs/v2, github.com/patrickhener/goshs, goshs.de/goshs
Critical
2 days ago
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
go
goshs.de/goshs, github.com/patrickhener/goshs/v2, goshs.de/goshs/v2
High
2 days ago
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
go
goshs.de/goshs/v2, goshs.de/goshs, github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs
Critical
2 days ago
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
go
goshs.de/goshs/v2, github.com/patrickhener/goshs/v2
High
2 days ago
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
pypi
datamodel-code-generator
High
2 days ago
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`
pypi
datamodel-code-generator
High
2 days ago
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
pypi
datamodel-code-generator
High
2 days ago
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
pypi
datamodel-code-generator
High
2 days ago
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data
pypi
datamodel-code-generator
High
2 days ago
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
pypi
datamodel-code-generator
High
2 days ago
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
pypi
datamodel-code-generator
High
2 days ago
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
pypi
datamodel-code-generator
High
2 days ago
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
pypi
datamodel-code-generator
Low
2 days ago
datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas
pypi
datamodel-code-generator
High
2 days ago
datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects
pypi
datamodel-code-generator
High
2 days ago
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
pypi
datamodel-code-generator
High
2 days ago
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
nuget
System.Security.Cryptography.Xml
Moderate
2 days ago
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
npm
@nocobase/plugin-collection-sql
Moderate
2 days ago
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
go
github.com/azukaar/cosmos-server
Moderate
2 days ago
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
go
github.com/azukaar/cosmos-server
Low
2 days ago
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
go
github.com/fission/fission
High
2 days ago
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
go
github.com/fission/fission
Moderate
2 days ago
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
go
github.com/fission/fission
High
2 days ago
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
go
github.com/fission/fission
High
2 days ago
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
nuget
SIPSorcery
Critical
2 days ago
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
packagist
poweradmin/poweradmin
High
2 days ago
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
npm, pypi, maven
qti-neon, com.quietterminal:qti-neon
High
2 days ago
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
rubygems
oauth2
High
2 days ago
OAuth: Cross-origin token-request redirects can expose signed request metadata
rubygems
oauth
Low
2 days ago
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
rubygems
sqlite3, sqlite3-ruby
Low
2 days ago
sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity
rubygems
sqlite3, sqlite3-ruby
Moderate
2 days ago
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
go
github.com/gopacket/gopacket
Moderate
2 days ago
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
go
github.com/gopacket/gopacket
Moderate
2 days ago
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
cargo
nono-cli
High
2 days ago
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
go, packagist
github.com/pterodactyl/wings, pterodactyl/panel
Moderate
2 days ago
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
npm
@novu/application-generic
High
2 days ago
Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)
packagist
pterodactyl/panel
High
2 days ago
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
maven
com.cedarpolicy:cedar-java
High
2 days ago
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
go
github.com/github/github-mcp-server
Filter by Severity
Filter by Source
Filter by Ecosystem
maven
7,914
npm
7,192
packagist
6,764
pypi
6,660
go
5,052
nuget
4,369
cargo
1,585
rubygems
1,094
hex
108
swift
58
actions
57
pub
11
Filter by Package
openclaw
591
moodle/moodle
437
tensorflow
433
tensorflow-cpu
410
tensorflow-gpu
398
magento/community-edition
360
org.jenkins-ci.main:jenkins-core
252
Microsoft.ChakraCore
247
github.com/mattermost/mattermost/server/v8
199
github.com/mattermost/mattermost-server
177
typo3/cms
163
Magick.NET-Q16-AnyCPU
162
Magick.NET-Q16-HDRI-AnyCPU
160
Magick.NET-Q16-HDRI-OpenMP-arm64
155
Magick.NET-Q16-HDRI-x64
153
org.apache.tomcat:tomcat
152
Magick.NET-Q16-HDRI-x86
151
com.liferay.portal:release.portal.bom
151
Magick.NET-Q16-HDRI-arm64
149
Magick.NET-Q16-OpenMP-arm64
147
wwbn/avideo
144
Magick.NET-Q16-OpenMP-x64
144
Magick.NET-Q16-arm64
142
Magick.NET-Q8-AnyCPU
142
Magick.NET-Q16-x86
141
n8n
139
Magick.NET-Q8-OpenMP-arm64
137
Magick.NET-Q16-x64
135
Magick.NET-Q8-x86
135
Magick.NET-Q8-arm64
134
Magick.NET-Q8-OpenMP-x64
133
pimcore/pimcore
132
open-webui
130
apache-airflow
127
dolibarr/dolibarr
126
Magick.NET-Q8-x64
125
com.liferay.portal:release.dxp.bom
124
concrete5/concrete5
120
typo3/cms-core
120
magento/project-community-edition
119
craftcms/cms
116
parse-server
116
phpmyadmin/phpmyadmin
107
drupal/core
107
Django
107
thorsten/phpmyfaq
105
microweber/microweber
105
librenms/librenms
100
org.keycloak:keycloak-services
97
code.gitea.io/gitea
94
silverstripe/framework
90
Magick.NET-Q16-HDRI-OpenMP-x64
90
symfony/symfony
89
flowise
85
com.fasterxml.jackson.core:jackson-databind
79
mlflow
78
gogs.io/gogs
75
github.com/usememos/memos
75
shopware/platform
74
mantisbt/mantisbt
74
drupal/drupal
73
getgrav/grav
69
salt
67
apache-superset
66
ansible
65
next
64
github.com/grafana/grafana
62
shopware/core
62
github.com/rancher/rancher
61
picklescan
59
actionpack
59
Magick.NET-Q16-OpenMP-x86
59
vllm
59
directus
58
github.com/siyuan-note/siyuan/kernel
58
org.apache.struts:struts2-core
58
snipe/snipe-it
57
org.apache.tomcat.embed:tomcat-embed-core
57
mautic/core
57
baserproject/basercms
56
nokogiri
56
froxlor/froxlor
55
github.com/hashicorp/vault
55
Plone
54
nocodb
54
surrealdb
52
rack
50
admidio/admidio
50
org.keycloak:keycloak-core
50
gradio
49
nova
49
django
49
pyload-ng
48
getkirby/cms
47
electron
47
org.xwiki.platform:xwiki-platform-oldcore
46
github.com/traefik/traefik/v2
45
matrix-synapse
45
org.elasticsearch:elasticsearch
44
vyper
44
aiohttp
44
rdiffweb
43
axios
43
hono
43
vm2
43
showdoc/showdoc
42
nilsteampassnet/teampass
42
pillow
42
k8s.io/kubernetes
42
github.com/filebrowser/filebrowser/v2
41
intelliants/subrion
41
phpmyfaq/phpmyfaq
41
plone
41
@budibase/server
40
github.com/zitadel/zitadel
39
io.undertow:undertow-core
39
github.com/traefik/traefik/v3
39
wasmtime
39
keystone
39
net.mingsoft:ms-mcms
39
praisonai
39
github.com/mattermost/mattermost-server/v6
38
com.thoughtworks.xstream:xstream
37
github.com/argoproj/argo-cd/v2
37
statamic/cms
37
github.com/cilium/cilium
37
PraisonAI
37
pypdf
37
com.jfinal:jfinal
36
ci4-cms-erp/ci4ms
36
deno
36
DotNetNuke.Core
36
moin
35
org.jenkins-ci.plugins:script-security
34
shopware/shopware
34
github.com/answerdev/answer
34
github.com/hashicorp/nomad
34
praisonaiagents
33
kimai/kimai
33
github.com/docker/docker
33
Pillow
33
code.vikunja.io/api
33
org.apache.tomcat:tomcat-catalina
32
github.com/hashicorp/consul
32
zendframework/zendframework1
32
langflow
32
prestashop/prestashop
31
org.opencms:opencms-core
31
github.com/argoproj/argo-cd
31
org.springframework.security:spring-security-core
31
phpoffice/phpspreadsheet
31
yeswiki/yeswiki
31
contao/core-bundle
31
opencv-python
31
undici
30
opencv-contrib-python
30
pocketmine/pocketmine-mp
30
org.apache.solr:solr-core
30
litellm
29
org.eclipse.jetty:jetty-server
29
mediawiki/core
28
pnpm
28
@anthropic-ai/claude-code
28
dompurify
27
github.com/nats-io/nats-server/v2
27
github.com/fleetdm/fleet/v4
27
centreon/centreon
27
zebrad
27
github.com/ethereum/go-ethereum
26
funadmin/funadmin
26
github.com/coder/coder/v2
26
github.com/openfga/openfga
26
pgadmin4
26
openmage/magento-lts
26
github.com/openbao/openbao
26
facturascripts/facturascripts
26
cockpit-hq/cockpit
26
org.keycloak:keycloak-parent
26
golang.org/x/crypto
25
grumpydictator/firefly-iii
25
ghost
25
laravel/framework
25
rubygems-update
25
openssl-src
25
org.apache.openmeetings:openmeetings-parent
25
astro
25
twig/twig
24
Microsoft.NetCore.App.Runtime.win-arm64
24
openbabel
24
Microsoft.NetCore.App.Runtime.win-x64
24
typo3/cms-backend
24
org.springframework:spring-webmvc
24
Microsoft.NetCore.App.Runtime.win-arm
24
org.bouncycastle:bcprov-jdk14
23
remdex/livehelperchat
23
magento/core
23
Microsoft.NetCore.App.Runtime.win-x86
23
github.com/goharbor/harbor
23
org.xwiki.platform:xwiki-platform-web-templates
23
puppet
23
Filter by Repository
https://github.com/tensorflow/tensorflow
433
https://github.com/moodle/moodle
250
https://github.com/xwiki/xwiki-platform
222
https://github.com/chakra-core/ChakraCore
214
https://github.com/jenkinsci/jenkins
178
https://github.com/liferay/liferay-portal
170
https://github.com/django/django
121
https://github.com/apache/tomcat
118
https://github.com/pimcore/pimcore
116
https://github.com/apache/airflow
105
https://github.com/TYPO3/typo3
93
https://github.com/keycloak/keycloak
90
https://github.com/microweber/microweber
90
https://github.com/librenms/librenms
77
https://github.com/rails/rails
70
https://github.com/FasterXML/jackson-databind
70
https://github.com/thorsten/phpmyfaq
69
https://github.com/silverstripe/silverstripe-framework
68
https://github.com/usememos/memos
68
https://github.com/kubernetes/kubernetes
66
https://github.com/symfony/symfony
64
https://github.com/Dolibarr/dolibarr
60
https://github.com/mattermost/mattermost
59
https://github.com/ansible/ansible
59
https://github.com/python-pillow/Pillow
52
https://github.com/spring-projects/spring-framework
51
https://github.com/argoproj/argo-cd
50
https://github.com/grafana/grafana
47
https://github.com/apache/struts
47
https://github.com/rancher/rancher
46
https://github.com/mautic/mautic
46
https://github.com/phpmyadmin/phpmyadmin
45
https://github.com/vyperlang/vyper
44
https://github.com/concretecms/concretecms
44
https://github.com/saltstack/salt
42
https://github.com/ikus060/rdiffweb
42
https://github.com/mantisbt/mantisbt
42
https://github.com/shopware/platform
42
https://github.com/craftcms/cms
41
https://github.com/directus/directus
41
https://github.com/shopware/shopware
40
https://github.com/star7th/showdoc
39
https://github.com/mmaitre314/picklescan
39
https://github.com/magento/magento2
38
https://github.com/dotnet/runtime
38
https://github.com/gradio-app/gradio
38
https://github.com/openstack/nova
38
https://github.com/plone/Products.CMFPlone
37
https://github.com/x-stream/xstream
37
https://github.com/mlflow/mlflow
36
https://github.com/octobercms/october
36
https://github.com/umbraco/Umbraco-CMS
35
https://github.com/sparklemotion/nokogiri
35
https://github.com/apache/activemq
34
https://github.com/answerdev/answer
34
https://github.com/parse-community/parse-server
34
https://github.com/opencv/opencv
32
https://github.com/go-gitea/gitea
32
https://github.com/matrix-org/synapse
32
https://github.com/cilium/cilium
31
https://github.com/apache/inlong
31
https://github.com/PaddlePaddle/Paddle
31
https://github.com/contao/contao
30
https://github.com/snipe/snipe-it
30
https://github.com/rack/rack
29
https://github.com/FlowiseAI/Flowise
28
https://github.com/openstack/keystone
28
https://github.com/electron/electron
28
https://github.com/CVEProject/cvelist
28
https://github.com/strapi/strapi
28
https://github.com/gogs/gogs
28
https://github.com/netty/netty
27
https://github.com/froxlor/froxlor
26
https://github.com/geoserver/geoserver
26
https://github.com/baserproject/basercms
26
https://github.com/github/advisory-database
26
https://github.com/zitadel/zitadel
26
https://github.com/apache/nifi
26
https://github.com/vllm-project/vllm
25
https://github.com/pmmp/PocketMine-MP
25
https://github.com/denoland/deno
25
https://github.com/langchain-ai/langchain
25
https://github.com/bcgit/bc-java
25
https://github.com/traefik/traefik
25
https://github.com/surrealdb/surrealdb
25
https://github.com/vercel/next.js
25
https://github.com/hashicorp/consul
24
https://github.com/apache/cxf
24
https://github.com/pyload/pyload
24
https://github.com/run-llama/llama_index
24
https://github.com/getgrav/grav
24
https://github.com/firefly-iii/firefly-iii
23
https://github.com/livehelperchat/livehelperchat
23
https://github.com/bytecodealliance/wasmtime
23
https://github.com/nilsteampassnet/TeamPass
23
https://github.com/moby/moby
23
https://github.com/TYPO3/TYPO3.CMS
23
https://github.com/dnnsoftware/Dnn.Platform
23
https://github.com/eclipse/jetty.project
23
https://github.com/PrestaShop/PrestaShop
23
https://github.com/getkirby/kirby
22
https://github.com/PHPOffice/PhpSpreadsheet
22
https://github.com/helm/helm
22
https://github.com/jenkinsci/script-security-plugin
22
https://github.com/nervosnetwork/ckb
22
https://github.com/goharbor/harbor
21
https://github.com/OpenZeppelin/openzeppelin-contracts
21
https://github.com/undertow-io/undertow
21
https://github.com/laravel/framework
21
https://github.com/hashicorp/vault
21
https://github.com/ethyca/fides
20
https://github.com/opencast/opencast
20
https://github.com/OpenNMS/opennms
20
https://github.com/jeecgboot/jeecg-boot
20
https://github.com/funadmin/funadmin
20
https://github.com/nilsteampassnet/teampass
19
https://github.com/huggingface/transformers
19
https://github.com/backstage/backstage
19
https://github.com/simplesamlphp/simplesamlphp
19
https://github.com/cloudfoundry/uaa
19
https://github.com/intelliants/subrion
19
https://github.com/TYPO3-CMS/core
19
https://github.com/containerd/containerd
19
https://github.com/alkacon/opencms-core
19
https://github.com/apache/camel
18
https://github.com/opencontainers/runc
18
https://github.com/vaadin/platform
18
https://github.com/OpenMage/magento-lts
18
https://github.com/rubygems/rubygems
18
https://github.com/openfga/openfga
17
https://github.com/mindsdb/mindsdb
17
https://github.com/liufee/cms
17
https://github.com/vantage6/vantage6
17
https://github.com/apache/kylin
17
https://github.com/ethereum/go-ethereum
17
https://github.com/etcd-io/etcd
16
https://github.com/quarkusio/quarkus
16
https://github.com/rusqlite/rusqlite
16
https://github.com/tinymce/tinymce
16
https://github.com/forkcms/forkcms
16
https://github.com/sequelize/sequelize
16
https://github.com/hashicorp/nomad
16
https://github.com/vitejs/vite
16
https://github.com/dotnet/aspnetcore
16
https://github.com/pyca/cryptography
16
https://github.com/yetiforcecompany/yetiforcecrm
16
https://github.com/zendframework/zendframework
15
https://github.com/containers/podman
15
https://github.com/xuxueli/xxl-job
15
https://github.com/aio-libs/aiohttp
15
https://github.com/puppetlabs/puppet
15
https://github.com/nodejs/undici
15
https://github.com/centreon/centreon
15
https://github.com/ckeditor/ckeditor4
15
https://github.com/thorsten/phpMyFAQ
15
https://github.com/spring-projects/spring-security
15
https://github.com/OPCFoundation/UA-.NETStandard
15
https://github.com/decidim/decidim
15
https://github.com/MobSF/Mobile-Security-Framework-MobSF
15
https://github.com/PHPMailer/PHPMailer
15
https://github.com/dompdf/dompdf
15
https://github.com/cobbler/cobbler
15
https://github.com/drupal/core
15
https://github.com/cockpit-hq/cockpit
14
https://github.com/rails/rails-html-sanitizer
14
https://github.com/Graylog2/graylog2-server
14
https://github.com/ImageMagick/ImageMagick
14
https://github.com/twisted/twisted
14
https://github.com/pgadmin-org/pgadmin4
14
https://github.com/dpgaspar/Flask-AppBuilder
14
https://github.com/cosmos/cosmos-sdk
14
https://github.com/ming-soft/MCMS
14
https://github.com/golang/go
14
https://github.com/urllib3/urllib3
14
https://github.com/janeczku/calibre-web
14
https://github.com/apache/superset
14
https://github.com/publify/publify
14
https://github.com/TryGhost/Ghost
14
https://github.com/pimcore/admin-ui-classic-bundle
14
https://github.com/apache/zeppelin
14
https://github.com/openbao/openbao
13
https://github.com/h2oai/h2o-3
13
https://github.com/OctoPrint/OctoPrint
13
https://github.com/zenml-io/zenml
13
https://github.com/1Panel-dev/1Panel
13
https://github.com/laurent22/joplin
13
https://github.com/apache/dolphinscheduler
13
https://github.com/dromara/hutool
13
https://github.com/OpenRefine/OpenRefine
13
https://github.com/swagger-api/swagger-ui
13
https://github.com/modoboa/modoboa
13
https://sourceforge.net/projects/phpmyadmin.sourceforge.net
12
https://github.com/puma/puma
12
https://github.com/smarty-php/smarty
12
https://github.com/igniterealtime/Openfire
12
https://github.com/openstack/glance
12
https://github.com/yiisoft/yii2
12
https://github.com/matrix-org/matrix-js-sdk
12
https://github.com/wagtail/wagtail
12