GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
418 advisories
Filter by severity
Mautic segment cloning doesn't have a proper permission check
Moderate
CVE-2024-47055
was published
for
mautic/core
(Composer)
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
Moderate
CVE-2025-5257
was published
for
mautic/core
(Composer)
May 28, 2025
Apache Commons Improper Access Control vulnerability
High
CVE-2025-48734
was published
for
commons-beanutils:commons-beanutils
(Maven)
May 28, 2025
Liferay Portal and Liferay DXP Bypass via Double Encoded URL
Moderate
CVE-2020-15840
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
May 24, 2022
Jenkins WildFly Deployer Plugin vulnerable to path traversal
Moderate
CVE-2022-41235
was published
for
org.jenkins-ci.plugins:wildfly-deployer
(Maven)
Sep 22, 2022
Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First Login
High
CVE-2025-23389
was published
for
github.com/rancher/rancher
(Go)
Feb 27, 2025
Mattermost allows a remote actor to make an arbitrary local channel read-only
Moderate
CVE-2024-41162
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 1, 2024
The femanager TYPO3 extension allows Insecure Direct Object Reference
Moderate
CVE-2025-48202
was published
for
in2code/femanager
(Composer)
May 21, 2025
Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens
Critical
CVE-2025-47884
was published
for
io.jenkins.plugins:oidc-provider
(Maven)
May 14, 2025
Reflex vulnerable to private state fields modification
High
CVE-2025-47425
was published
for
reflex
(pip)
May 15, 2025
Liferay DXP Vulnerable to Denial-of-service (DoS) in the Multi-Factor Authentication Module
Moderate
CVE-2021-29041
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Jenkins Compuware Topaz for Total Test Plugin vulnerable to Protection Mechanism Failure
High
CVE-2022-43429
was published
for
com.compuware.jenkins:compuware-topaz-for-total-test
(Maven)
Oct 19, 2022
goshs route not protected, allows command execution
Critical
CVE-2025-46816
was published
for
github.com/patrickhener/goshs
(Go)
May 6, 2025
WildFly improper RBAC permission
Moderate
CVE-2025-23367
was published
for
org.wildfly.core:wildfly-server
(Maven)
Jan 31, 2025
BRCC Incorrect Access Control vulnerability
Critical
CVE-2025-45616
was published
for
com.baidu.mapp:brcc-core
(Maven)
May 5, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-46331
was published
for
github.com/openfga/openfga
(Go)
Apr 30, 2025
Missing permissions check in Liferay Portal
Moderate
CVE-2022-42126
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Vite allows server.fs.deny to be bypassed with .svg or relative paths
Moderate
CVE-2025-31486
was published
for
vite
(npm)
Apr 4, 2025
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
Moderate
CVE-2022-47407
was published
for
fixpunkt/fp-masterquiz
(Composer)
Dec 14, 2022
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24436
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24437
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
High
CVE-2014-6289
was published
for
dl/yag
(Composer)
May 17, 2022
Moodle does not use the forceloginforprofiles setting for course-profiles access control
Moderate
CVE-2011-4279
was published
for
moodle/moodle
(Composer)
May 13, 2022
Frontend User Registration extension for TYPO3 does not properly verify access rights
High
CVE-2009-1264
was published
for
sjbr/sr-feuser-register
(Composer)
May 2, 2022
Joomla! allows attackers to access cached pages
Moderate
CVE-2008-3226
was published
for
joomla/joomla-platform
(Composer)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API