GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
271 advisories
Filter by severity
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is...
High
Unreviewed
CVE-2025-4519
was published
Nov 7, 2025
Hono Improper Authorization vulnerability
High
CVE-2025-62610
was published
for
hono
(npm)
Oct 22, 2025
Redis Enterprise Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-59271
was published
Oct 9, 2025
Casdoor is vulnerable to Improper Authorization
High
CVE-2025-61524
was published
for
github.com/casdoor/casdoor
(Go)
Oct 8, 2025
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317...
High
Unreviewed
CVE-2025-59305
was published
Sep 24, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due...
High
Unreviewed
CVE-2025-26430
was published
Sep 5, 2025
GitProxy New Branch Approval Exploit
High
CVE-2025-54585
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
HAX CMS API Lacks Authorization Checks
High
CVE-2025-54378
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 25, 2025
The Application is vulnerable to an Unauthenticated Arbitrary File Read. This affects the
Agent...
High
Unreviewed
CVE-2024-26291
was published
Jul 14, 2025
Juju allows arbitrary executable uploads via authenticated endpoint without authorization
High
CVE-2025-0928
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute...
High
Unreviewed
CVE-2025-49701
was published
Jul 8, 2025
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without...
High
Unreviewed
CVE-2025-6713
was published
Jul 7, 2025
Graylog vulnerable to privilege escalation through API tokens
High
CVE-2025-53106
was published
for
org.graylog2:graylog2-server
(Maven)
Jun 30, 2025
Claude Code Improper Authorization via websocket connections from arbitrary origins
High
CVE-2025-52882
was published
for
@anthropic-ai/claude-code
(npm)
Jun 23, 2025
Salt vulnerable to arbitrary event injection
High
CVE-2025-22239
was published
for
salt
(pip)
Jun 13, 2025
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization...
High
Unreviewed
CVE-2025-46840
was published
Jun 11, 2025
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a...
High
Unreviewed
CVE-2024-43706
was published
Jun 10, 2025
Magento Improper Authorization leading to security feature bypass
High
CVE-2025-43585
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing...
High
Unreviewed
CVE-2025-4103
was published
May 31, 2025
The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to...
High
Unreviewed
CVE-2025-4672
was published
May 31, 2025
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a...
High
Unreviewed
CVE-2025-4474
was published
May 13, 2025
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a...
High
Unreviewed
CVE-2025-4473
was published
May 13, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An...
High
Unreviewed
CVE-2025-31249
was published
May 13, 2025
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized...
High
Unreviewed
CVE-2025-3921
was published
May 7, 2025
ProTip!
Advisories are also available from the
GraphQL API