GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,862 advisories
Filter by severity
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-2424
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 14, 2025
Mattermost Fails to Restrict Certain Operations on System Admins
Moderate
CVE-2025-32093
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 14, 2025
Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint
Low
CVE-2025-24866
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 10, 2025
Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
Critical
CVE-2022-47408
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed...
High
Unreviewed
CVE-2022-23741
was published
Dec 14, 2022
Denial of service in Modem module due to improper authorization while error handling in...
High
Unreviewed
CVE-2022-25685
was published
Dec 13, 2022
In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A...
High
Unreviewed
CVE-2025-32408
was published
Apr 21, 2025
An access issue was addressed with additional sandbox restrictions on third-party apps. This...
Moderate
Unreviewed
CVE-2022-32945
was published
Dec 15, 2022
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an...
High
Unreviewed
CVE-2025-43922
was published
Apr 21, 2025
An access issue existed with privileged API calls. This issue was addressed with additional...
High
Unreviewed
CVE-2022-42849
was published
Dec 15, 2022
Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux...
Moderate
Unreviewed
CVE-2024-12862
was published
Apr 21, 2025
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation...
High
Unreviewed
CVE-2017-0910
was published
May 13, 2022
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs)....
Moderate
Unreviewed
CVE-2017-10379
was published
May 14, 2022
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users...
High
Unreviewed
CVE-2017-7505
was published
May 13, 2022
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound...
High
Unreviewed
CVE-2017-4915
was published
May 13, 2022
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public...
Moderate
Unreviewed
CVE-2017-0894
was published
May 13, 2022
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS...
Moderate
Unreviewed
CVE-2017-6590
was published
May 13, 2022
An error in the implementation of an autosubscribe feature in the check_stream_exists route of...
Moderate
Unreviewed
CVE-2017-0881
was published
May 13, 2022
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by...
Moderate
Unreviewed
CVE-2017-6816
was published
May 13, 2022
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate...
High
Unreviewed
CVE-2025-43917
was published
Apr 19, 2025
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change...
Low
Unreviewed
CVE-2022-20558
was published
Dec 21, 2022
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to...
Moderate
Unreviewed
CVE-2022-20572
was published
Dec 21, 2022
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated...
Moderate
Unreviewed
CVE-2024-49808
was published
Apr 18, 2025
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is...
High
Unreviewed
CVE-2021-32960
was published
Apr 3, 2022
ProTip!
Advisories are also available from the
GraphQL API