GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,855 advisories
Filter by severity
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24233
was published
Apr 1, 2025
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing
High
CVE-2025-31694
was published
for
drupal/tfa
(Composer)
Apr 1, 2025
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before...
High
Unreviewed
CVE-2025-30093
was published
Mar 27, 2025
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior...
High
Unreviewed
CVE-2025-2242
was published
Mar 27, 2025
An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have...
Moderate
Unreviewed
CVE-2024-55965
was published
Mar 26, 2025
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an...
Critical
Unreviewed
CVE-2025-1542
was published
Mar 26, 2025
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
Cilium node based network policies may incorrectly allow workload traffic
Low
CVE-2025-30163
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Mar 24, 2025
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Low
CVE-2025-30162
was published
for
github.com/cilium/cilium
(Go)
Mar 24, 2025
Authorization Bypass in Next.js Middleware
Critical
CVE-2025-29927
was published
for
next
(npm)
Mar 21, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public
Moderate
CVE-2025-27933
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 21, 2025
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
Low
CVE-2025-27715
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Enforce Certain Search APIs
Moderate
CVE-2025-30179
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
Moderate
CVE-2025-24920
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels
Moderate
CVE-2025-25274
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14...
High
Unreviewed
CVE-2024-44305
was published
Mar 21, 2025
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
Moderate
Unreviewed
CVE-2025-26853
was published
Mar 20, 2025
An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc...
Moderate
Unreviewed
CVE-2024-9159
was published
Mar 20, 2025
In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where...
High
Unreviewed
CVE-2024-9098
was published
Mar 20, 2025
Open WebUI Allows Admin Deletion via API Endpoint
High
CVE-2024-7039
was published
for
open-webui
(pip)
Mar 20, 2025
In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with...
Moderate
Unreviewed
CVE-2024-10273
was published
Mar 20, 2025
In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct...
High
Unreviewed
CVE-2024-10275
was published
Mar 20, 2025
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low...
High
Unreviewed
CVE-2024-10109
was published
Mar 20, 2025
XWiki uses the wrong wiki reference in AuthorizationManager
High
CVE-2025-29924
was published
for
org.xwiki.platform:xwiki-platform-security-authorization-api
(Maven)
Mar 19, 2025
ProTip!
Advisories are also available from the
GraphQL API