GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            3,945 advisories
        Filter by severity
        
      
      
    
                    
                      Zitadel May Bypass Second Authentication Factor
                    
                      
  High
                    
                
                      
                        CVE-2025-64103
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel/v2
                        
                        (Go)
                      Oct 29, 2025 
                    
                  
                    
                      FastMCP Auth Integration Allows for Confused Deputy Account Takeover
                    
                      
  High
                    
                
                      
                        GHSA-c2jp-c369-7pvx
                      
                      was published
                        for
                        
                          fastmcp
                        
                        (pip)
                      Oct 29, 2025 
                    
                  
                    
                      A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60424
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43995
                      
                      was published
                      Oct 24, 2025 
                    
                  
                    
                      Captive Portal can allow authentication bypass
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6979
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Moodle does not properly enforce MFA
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62398
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Oct 23, 2025 
                    
                  
                    
                      TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-56447
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-41108
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-41110
                      
                      was published
                      Oct 22, 2025 
                    
                  
                    
                      Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017,...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60772
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11625
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11942
                      
                      was published
                      Oct 19, 2025 
                    
                  
                    
                      A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11852
                      
                      was published
                      Oct 16, 2025 
                    
                  
                    
                      PrestaShop Checkout allows customer account takeover via email
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61922
                      
                      was published
                        for
                        
                          prestashop/ps_checkout
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6....
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-43281
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-10293
                      
                      was published
                      Oct 15, 2025 
                    
                  
                    
                      Improper authentication in Windows SMB Client allows an unauthorized attacker to perform...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-59280
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55340
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53845
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      An authentication bypass security issue exists within FactoryTalk View Machine Edition  Web...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9063
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      A path traversal security issue exists within FactoryTalk View Machine Edition, allowing...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9064
                      
                      was published
                      Oct 14, 2025 
                    
                  
                    
                      A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9265
                      
                      was published
                      Oct 13, 2025 
                    
                  
                    
                      A vulnerability was found in ProjectsAndPrograms School Management System up to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11661
                      
                      was published
                      Oct 13, 2025 
                    
                  
                    
                      A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11633
                      
                      was published
                      Oct 12, 2025 
                    
                  
                    
                      A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11529
                      
                      was published
                      Oct 9, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API