GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,072 advisories
Filter by severity
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0....
Moderate
Unreviewed
CVE-2025-5059
was published
May 22, 2025
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been...
Moderate
Unreviewed
CVE-2025-5299
was published
May 28, 2025
Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code...
Moderate
Unreviewed
CVE-2022-35621
was published
Sep 22, 2022
A vulnerability, which was classified as critical, has been found in SourceCodester Client...
Moderate
Unreviewed
CVE-2025-4923
was published
May 19, 2025
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-4735
was published
May 16, 2025
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5...
Moderate
Unreviewed
CVE-2022-32880
was published
Sep 21, 2022
An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2025-45343
was published
May 28, 2025
Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may...
Moderate
Unreviewed
CVE-2023-45210
was published
Dec 6, 2023
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by...
Moderate
Unreviewed
CVE-2025-3123
was published
Apr 3, 2025
Jenkins WildFly Deployer Plugin vulnerable to path traversal
Moderate
CVE-2022-41235
was published
for
org.jenkins-ci.plugins:wildfly-deployer
(Maven)
Sep 22, 2022
Liferay Portal and Liferay DXP Bypass via Double Encoded URL
Moderate
CVE-2020-15840
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
May 24, 2022
Apache Commons Improper Access Control vulnerability
High
CVE-2025-48734
was published
for
commons-beanutils:commons-beanutils
(Maven)
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
Moderate
CVE-2025-5257
was published
for
mautic/core
(Composer)
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
Moderate
CVE-2024-47055
was published
for
mautic/core
(Composer)
May 28, 2025
A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This...
Moderate
Unreviewed
CVE-2024-13191
was published
Jan 9, 2025
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12...
Moderate
Unreviewed
CVE-2022-32883
was published
Sep 21, 2022
An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2022-32834
was published
Aug 25, 2022
Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier...
High
Unreviewed
CVE-2025-4433
was published
May 30, 2025
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the...
Moderate
Unreviewed
CVE-2022-45164
was published
Jan 10, 2023
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different...
High
Unreviewed
CVE-2022-36441
was published
Jan 10, 2023
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the...
High
Unreviewed
CVE-2022-36443
was published
Jan 10, 2023
An issue was discovered in Zebra Enterprise Home Screen 4.1.19. By using the embedded Google...
Moderate
Unreviewed
CVE-2022-36442
was published
Jan 10, 2023
An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the...
Moderate
Unreviewed
CVE-2022-45166
was published
Jan 10, 2023
Incorrect access control in M2Soft CROWNIX Report & ERS affected v7.x to v7.4.3.599 and v8.x to...
Moderate
Unreviewed
CVE-2024-57336
was published
May 28, 2025
ProTip!
Advisories are also available from the
GraphQL API