GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
252 advisories
Filter by severity
MantisBT unauthorized disclosure of private project column configuration
Moderate
CVE-2025-62520
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Moodle has a time restriction bypass
Moderate
CVE-2025-62401
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Hono Improper Authorization vulnerability
High
CVE-2025-62610
was published
for
hono
(npm)
Oct 22, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
Critical
CVE-2025-61928
was published
for
better-auth
(npm)
Oct 9, 2025
Casdoor is vulnerable to Improper Authorization
High
CVE-2025-61524
was published
for
github.com/casdoor/casdoor
(Go)
Oct 8, 2025
XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
Critical
CVE-2025-49594
was published
for
org.xwiki.contrib.oidc:oidc-authenticator
(Maven)
Oct 6, 2025
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
Low
GHSA-q6hv-wcjr-wp8h
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 26, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Moderate
CVE-2025-55675
was published
for
apache-superset
(pip)
Aug 14, 2025
GitProxy New Branch Approval Exploit
High
CVE-2025-54585
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
HAX CMS API Lacks Authorization Checks
High
CVE-2025-54378
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 25, 2025
Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
Moderate
CVE-2025-53889
was published
for
directus
(npm)
Jul 15, 2025
Juju allows arbitrary executable uploads via authenticated endpoint without authorization
High
CVE-2025-0928
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Graylog vulnerable to privilege escalation through API tokens
High
CVE-2025-53106
was published
for
org.graylog2:graylog2-server
(Maven)
Jun 30, 2025
Claude Code Improper Authorization via websocket connections from arbitrary origins
High
CVE-2025-52882
was published
for
@anthropic-ai/claude-code
(npm)
Jun 23, 2025
Salt vulnerable to arbitrary event injection
High
CVE-2025-22239
was published
for
salt
(pip)
Jun 13, 2025
Magento Improper Authorization leading to security feature bypass
High
CVE-2025-43585
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
Grafana's datasource proxy API allows authorization checks to be bypassed
Moderate
CVE-2025-3454
was published
for
github.com/grafana/grafana
(Go)
Jun 2, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-48371
was published
for
github.com/openfga/openfga
(Go)
May 23, 2025
XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming right
Moderate
CVE-2025-48063
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-bridge
(Maven)
May 21, 2025
Apache Superset Allows Ownership Takeover
Moderate
CVE-2025-27696
was published
for
apache-superset
(pip)
May 13, 2025
Inspektor Gadget Security Policies Can be Bypassed
Moderate
GHSA-pv22-fqcj-7xwh
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
May 6, 2025
Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
Moderate
CVE-2025-4210
was published
for
github.com/casdoor/casdoor
(Go)
May 2, 2025
The lesscss script service allows cache clearing without programming right
Low
CVE-2025-32972
was published
for
org.xwiki.platform:xwiki-platform-lesscss-script
(Maven)
Apr 29, 2025
ProTip!
Advisories are also available from the
GraphQL API