GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,687 advisories
        Filter by severity
        
      
      
    
                    
                      A vulnerability was identified in code-projects Simple Online Hotel Reservation System 2.0. The...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12593
                      
                      was published
                      Nov 2, 2025 
                    
                  
                    
                      Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-63562
                      
                      was published
                      Oct 31, 2025 
                    
                  
                    
                      Silver has unrestricted traffic between Wireguard clients
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-27093
                      
                      was published
                        for
                        
                          github.com/bishopfox/sliver
                        
                        (Go)
                      Oct 28, 2025 
                    
                  
                    
                      A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12378
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      A flaw has been found in MaxSite CMS up to 109. This issue affects some unknown processing of the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12347
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      A vulnerability has been found in Yonyou U8 Cloud up to 5.1sp. The impacted element is an unknown...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12344
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      A vulnerability was detected in MaxSite CMS up to 109. This vulnerability affects unknown code of...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12346
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12331
                      
                      was published
                      Oct 28, 2025 
                    
                  
                    
                      IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-60982
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54970
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0....
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12301
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-37749
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12291
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca....
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12268
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      A security vulnerability has been detected in Bdtask Flight Booking Software up to 3.1. Affected...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12222
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      A vulnerability was detected in Bdtask Flight Booking Software up to 3.1. This affects an unknown...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12223
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-12201
                      
                      was published
                      Oct 27, 2025 
                    
                  
                    
                      The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-6680
                      
                      was published
                      Oct 25, 2025 
                    
                  
                    
                      Moodle course access permissions are not properly checked in course_output_fragment_course_overview
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62393
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Oct 23, 2025 
                    
                  
                    
                      A flaw in the cohort search web service allowed users with permissions in lower contexts to...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-62395
                      
                      was published
                      Oct 23, 2025 
                    
                  
                    
                      Vulnerability in the PeopleSoft Enterprise FIN Payables product of Oracle PeopleSoft (component:...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61762
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61881
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component:...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53071
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61761
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      Vulnerability in the PeopleSoft Enterprise FIN IT Asset Management product of Oracle PeopleSoft ...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61758
                      
                      was published
                      Oct 21, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API