GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,277 advisories
Filter by severity
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to...
Moderate
Unreviewed
CVE-2025-4019
was published
Apr 28, 2025
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to...
Moderate
Unreviewed
CVE-2025-4018
was published
Apr 28, 2025
Moodle self enrollment available before completing second factor with MFA enabled
Moderate
CVE-2025-3634
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle makes some user data available before completing second factor with MFA enabled
Moderate
CVE-2025-3627
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2025-2771
was published
Apr 23, 2025
A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue...
Moderate
Unreviewed
CVE-2025-3850
was published
Apr 22, 2025
Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that...
Moderate
Unreviewed
CVE-2025-30733
was published
Apr 15, 2025
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass...
Moderate
Unreviewed
CVE-2024-44843
was published
Apr 15, 2025
In JotUrl 2.0, is possible to bypass security requirements during the password change process.
Moderate
Unreviewed
CVE-2025-24949
was published
Apr 15, 2025
In WhatsUp Gold versions released before 2024.0.3, a
database manipulation
vulnerability...
Moderate
Unreviewed
CVE-2025-2572
was published
Apr 14, 2025
Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header...
Moderate
Unreviewed
CVE-2025-22232
was published
Apr 10, 2025
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-3268
was published
Apr 4, 2025
Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.
Moderate
Unreviewed
CVE-2025-3061
was published
Apr 1, 2025
Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.
Moderate
Unreviewed
CVE-2025-3062
was published
Apr 1, 2025
A logic issue was addressed with improved state management. This issue is fixed in visionOS 2.4,...
Moderate
Unreviewed
CVE-2025-30432
was published
Apr 1, 2025
An attacker with access to the network where the vulnerable device is located could capture...
Moderate
Unreviewed
CVE-2025-2859
was published
Mar 28, 2025
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that...
Moderate
Unreviewed
CVE-2024-12869
was published
Mar 20, 2025
Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore...
Moderate
Unreviewed
CVE-2025-26475
was published
Mar 19, 2025
A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by...
Moderate
Unreviewed
CVE-2025-2388
was published
Mar 17, 2025
A vulnerability, which was classified as critical, has been found in IROAD Dash Cam X5 and Dash...
Moderate
Unreviewed
CVE-2025-2344
was published
Mar 16, 2025
A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This...
Moderate
Unreviewed
CVE-2025-2339
was published
Mar 16, 2025
Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
Moderate
CVE-2025-29773
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Mar 10, 2025
An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to...
Moderate
Unreviewed
CVE-2025-25450
was published
Mar 6, 2025
ProTip!
Advisories are also available from the
GraphQL API