GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,704
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
69 advisories
Filter by severity
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16...
Moderate
Unreviewed
CVE-2024-1525
was published
Feb 22, 2024
The affected product is vulnerable to an attacker modifying the bootloader by using custom...
Moderate
Unreviewed
CVE-2024-38279
was published
Jun 13, 2024
svix vulnerable to Authentication Bypass
Moderate
CVE-2024-21491
was published
for
svix
(Rust)
Feb 13, 2024
IBM Cognos Controller 11.0.0 and 11.0.1
could allow an authenticated user with local access...
Moderate
Unreviewed
CVE-2024-25036
was published
Dec 3, 2024
The web server of affected devices do not properly authenticate user request to the '/ClientArea...
Moderate
Unreviewed
CVE-2024-46887
was published
Oct 8, 2024
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication...
Moderate
Unreviewed
CVE-2025-24456
was published
Jan 21, 2025
Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password...
Moderate
Unreviewed
CVE-2025-26700
was published
Feb 17, 2025
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2023-23503
was published
Feb 27, 2023
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that...
Moderate
Unreviewed
CVE-2023-50915
was published
Apr 30, 2024
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus...
Moderate
Unreviewed
CVE-2022-3614
was published
Jan 3, 2023
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to...
Moderate
Unreviewed
CVE-2025-32357
was published
Apr 5, 2025
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions...
Moderate
Unreviewed
CVE-2017-6871
was published
May 13, 2022
@account-kit/smart-contracts Allowlist Module Bypass Vulnerability
Moderate
GHSA-wfm2-rq5g-f8v5
was published
for
@account-kit/smart-contracts
(npm)
Apr 29, 2025
Missing Role Based Access Control for the REST handlers in bleve/http package
Moderate
CVE-2022-31022
was published
for
github.com/blevesearch/bleve
(Go)
Jun 3, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to...
Moderate
Unreviewed
CVE-2025-0549
was published
May 9, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo -...
Moderate
Unreviewed
CVE-2024-33939
was published
May 19, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48011
was published
May 21, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48010
was published
May 21, 2025
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover...
Moderate
Unreviewed
CVE-2025-48926
was published
May 28, 2025
Vulnerability that cards can call unauthorized APIs in the FRS process
Impact: Successful...
Moderate
Unreviewed
CVE-2025-48904
was published
Jun 6, 2025
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2024-13772
was published
Mar 14, 2025
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-5820
was published
Jun 23, 2025
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a...
Moderate
Unreviewed
CVE-2025-6556
was published
Jun 24, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA -...
Moderate
Unreviewed
CVE-2025-6675
was published
Jun 26, 2025
ProTip!
Advisories are also available from the
GraphQL API