GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,855 advisories
Filter by severity
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an...
High
Unreviewed
CVE-2025-43922
was published
Apr 21, 2025
Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux...
Moderate
Unreviewed
CVE-2024-12862
was published
Apr 21, 2025
In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A...
High
Unreviewed
CVE-2025-32408
was published
Apr 21, 2025
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create...
Moderate
Unreviewed
CVE-2025-43921
was published
Apr 20, 2025
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate...
High
Unreviewed
CVE-2025-43917
was published
Apr 19, 2025
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated...
Moderate
Unreviewed
CVE-2024-49808
was published
Apr 18, 2025
The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products –...
Moderate
Unreviewed
CVE-2025-3453
was published
Apr 17, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-2564
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-27571
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-24839
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Low
Unreviewed
CVE-2025-30703
was published
Apr 15, 2025
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2025-21582
was published
Apr 15, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-2424
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 14, 2025
Mattermost Fails to Restrict Certain Operations on System Admins
Moderate
CVE-2025-32093
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 14, 2025
Incorrect Authorization vulnerability in The Wikimedia Foundation Mediawiki - OAuth Extension...
Critical
Unreviewed
CVE-2025-32068
was published
Apr 11, 2025
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Low
CVE-2025-24866
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 10, 2025
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization...
High
Unreviewed
CVE-2025-26330
was published
Apr 10, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
GHSA-6jrf-4jv4-r9mw
was published
for
tendermint-light-client-verifier
(Rust)
Apr 9, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions...
Moderate
Unreviewed
CVE-2025-31331
was published
Apr 8, 2025
GraphQL query operations security can be bypassed
High
CVE-2025-31481
was published
for
api-platform/core
(Composer)
Apr 4, 2025
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of...
Critical
Unreviewed
CVE-2024-38392
was published
Apr 2, 2025
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Low
CVE-2025-27427
was published
for
org.apache.activemq:artemis-server
(Maven)
Apr 1, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and...
Low
Unreviewed
CVE-2025-30469
was published
Apr 1, 2025
This issue was addressed with improved data access restriction. This issue is fixed in visionOS 2...
High
Unreviewed
CVE-2025-24221
was published
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API