GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,857 advisories
Filter by severity
Duplicate Advisory: SurrealDB is Vulnerable to Unauthorized Data Exposure via LIVE Query Subscriptions
Moderate
GHSA-98f8-j56x-2hh4
was published
for
surrealdb
(Rust)
Sep 26, 2025
•
withdrawn
Liferay Portal and DXP does not properly check permission with import and export tasks
Moderate
CVE-2025-43806
was published
for
com.liferay:com.liferay.batch.engine.service
(Maven)
Sep 23, 2025
In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can...
Moderate
Unreviewed
CVE-2025-59714
was published
Sep 19, 2025
An authenticated attacker granted a Viewer or Auditor role on a BIG-IQ can upload arbitrary files...
Moderate
Unreviewed
CVE-2023-29240
was published
Jul 6, 2023
Access permission verification vulnerability in the App Multiplier module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-9136
was published
Sep 27, 2024
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of...
High
Unreviewed
CVE-2025-10016
was published
Sep 16, 2025
The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private...
Moderate
Unreviewed
CVE-2025-10015
was published
Sep 16, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Low
CVE-2025-43789
was published
for
com.liferay:com.liferay.comment.web
(Maven)
Sep 12, 2025
Liferay Portal's Incorrect Authorization vulnerability can lead to guest users to obtaining sensitive data
Moderate
CVE-2025-43784
was published
for
com.liferay:com.liferay.headless.builder.impl
(Maven)
Sep 10, 2025
A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of...
Moderate
Unreviewed
CVE-2025-9602
was published
Aug 29, 2025
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
Critical
CVE-2024-38002
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Next.js authorization bypass vulnerability
High
CVE-2024-51479
was published
for
next
(npm)
Dec 17, 2024
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated...
Moderate
Unreviewed
CVE-2025-58134
was published
Sep 10, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Incorrect Authorization...
Moderate
Unreviewed
CVE-2025-54246
was published
Sep 9, 2025
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect...
Moderate
Unreviewed
CVE-2025-26442
was published
Sep 5, 2025
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an...
High
Unreviewed
CVE-2025-26436
was published
Sep 5, 2025
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due...
High
Unreviewed
CVE-2025-32333
was published
Sep 4, 2025
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without...
High
Unreviewed
CVE-2025-48523
was published
Sep 4, 2025
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with...
High
Unreviewed
CVE-2025-23256
was published
Sep 5, 2025
NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with...
Moderate
Unreviewed
CVE-2025-23262
was published
Sep 5, 2025
A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function...
Moderate
Unreviewed
CVE-2025-9835
was published
Sep 3, 2025
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user...
High
Unreviewed
CVE-2024-7697
was published
Aug 12, 2024
ProTip!
Advisories are also available from the
GraphQL API