GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,821
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,004
Swift
38
Unreviewed advisories
All unreviewed
5,000+
337 advisories
Filter by severity
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2025-8401
was published
Jul 31, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-7938
was published
Jul 21, 2025
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web...
Moderate
Unreviewed
CVE-2025-50073
was published
Jul 15, 2025
Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
Moderate
CVE-2025-53889
was published
for
directus
(npm)
Jul 15, 2025
Secure-upload is a data submission service that validates single-use tokens when accepting...
Moderate
Unreviewed
CVE-2025-53709
was published
Jul 10, 2025
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE)...
Moderate
Unreviewed
CVE-2025-20264
was published
Jun 26, 2025
When a link can be opened in an external application, Firefox for Android will, by default,...
Moderate
Unreviewed
CVE-2025-6431
was published
Jun 26, 2025
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated...
Moderate
Unreviewed
CVE-2025-6329
was published
Jun 20, 2025
Grafana's datasource proxy API allows authorization checks to be bypassed
Moderate
CVE-2025-3454
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1...
Moderate
Unreviewed
CVE-2025-5182
was published
May 26, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-48371
was published
for
github.com/openfga/openfga
(Go)
May 23, 2025
XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming right
Moderate
CVE-2025-48063
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-bridge
(Maven)
May 21, 2025
Apache Superset Allows Ownership Takeover
Moderate
CVE-2025-27696
was published
for
apache-superset
(pip)
May 13, 2025
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized access...
Moderate
Unreviewed
CVE-2025-3924
was published
May 7, 2025
Inspektor Gadget Security Policies Can be Bypassed
Moderate
GHSA-pv22-fqcj-7xwh
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
May 6, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
Moderate
CVE-2025-4210
was published
for
github.com/casdoor/casdoor
(Go)
May 2, 2025
Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and...
Moderate
Unreviewed
CVE-2023-42973
was published
Apr 11, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
Moderate
CVE-2025-30373
was published
for
org.graylog2:graylog2-server
(Maven)
Apr 7, 2025
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege...
Moderate
Unreviewed
CVE-2025-28131
was published
Apr 1, 2025
Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows...
Moderate
Unreviewed
CVE-2025-2600
was published
Mar 26, 2025
Kyverno ignores subjectRegExp and IssuerRegExp
Moderate
CVE-2025-29778
was published
for
github.com/kyverno/kyverno
(Go)
Mar 24, 2025
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to...
Moderate
Unreviewed
CVE-2024-13060
was published
Mar 20, 2025
An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me...
Moderate
Unreviewed
CVE-2024-10274
was published
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API