GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
768 advisories
Filter by severity
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without...
High
Unreviewed
CVE-2025-6713
was published
Jul 7, 2025
Graylog vulnerable to privilege escalation through API tokens
High
CVE-2025-53106
was published
for
org.graylog2:graylog2-server
(Maven)
Jun 30, 2025
CRI-O: Maliciously structured checkpoint file can gain arbitrary node access
Moderate
CVE-2024-8676
was published
for
github.com/cri-o/cri-o
(Go)
Nov 26, 2024
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of...
Low
Unreviewed
CVE-2025-4654
was published
Jul 2, 2025
Claude Code Improper Authorization via websocket connections from arbitrary origins
High
CVE-2025-52882
was published
for
@anthropic-ai/claude-code
(npm)
Jun 23, 2025
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE)...
Moderate
Unreviewed
CVE-2025-20264
was published
Jun 26, 2025
When a link can be opened in an external application, Firefox for Android will, by default,...
Moderate
Unreviewed
CVE-2025-6431
was published
Jun 26, 2025
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated...
Moderate
Unreviewed
CVE-2025-6329
was published
Jun 20, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-48371
was published
for
github.com/openfga/openfga
(Go)
May 23, 2025
Salt vulnerable to arbitrary event injection
High
CVE-2025-22239
was published
for
salt
(pip)
Jun 13, 2025
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization...
High
Unreviewed
CVE-2025-46840
was published
Jun 11, 2025
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with...
Moderate
Unreviewed
CVE-2023-43609
was published
Feb 9, 2024
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a...
High
Unreviewed
CVE-2024-43706
was published
Jun 10, 2025
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress...
Moderate
Unreviewed
CVE-2024-9531
was published
Oct 24, 2024
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role...
Moderate
Unreviewed
CVE-2024-22021
was published
Feb 7, 2024
Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges...
Critical
Unreviewed
CVE-2025-29827
was published
May 9, 2025
Grafana's datasource proxy API allows authorization checks to be bypassed
Moderate
CVE-2025-3454
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
Moodle allows users to retrieve information they did not have permission to access
Moderate
CVE-2024-45689
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). ...
Moderate
Unreviewed
CVE-2024-20979
was published
Jan 17, 2024
A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1...
Moderate
Unreviewed
CVE-2025-5182
was published
May 26, 2025
The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing...
High
Unreviewed
CVE-2025-4103
was published
May 31, 2025
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing...
Critical
Unreviewed
CVE-2025-4631
was published
May 31, 2025
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to...
High
Unreviewed
CVE-2025-4672
was published
May 31, 2025
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4...
High
Unreviewed
CVE-2022-26773
was published
May 27, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey...
Moderate
Unreviewed
CVE-2022-32838
was published
Aug 25, 2022
ProTip!
Advisories are also available from the
GraphQL API