GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
768 advisories
Filter by severity
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-11521
was published
Nov 11, 2025
Incorrect security UI in Omnibox in Google Chrome on Android prior to 142.0.7444.59 allowed a...
Moderate
Unreviewed
CVE-2025-12435
was published
Nov 10, 2025
Magento is affected by an improper authorization vulnerability
Moderate
CVE-2021-36037
was published
for
magento/community-edition
(Composer)
May 24, 2022
In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System...
Critical
Unreviewed
CVE-2025-63691
was published
Nov 7, 2025
A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-12854
was published
Nov 7, 2025
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is...
High
Unreviewed
CVE-2025-4519
was published
Nov 7, 2025
Magento improper authorization vulnerability
High
CVE-2021-36029
was published
for
magento/community-edition
(Composer)
May 24, 2022
A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-7938
was published
Jul 21, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39405
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39404
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39418
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39413
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39407
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-12360
was published
Nov 6, 2025
MantisBT unauthorized disclosure of private project column configuration
Moderate
CVE-2025-62520
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Moderate
CVE-2025-55675
was published
for
apache-superset
(pip)
Aug 14, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app...
Moderate
Unreviewed
CVE-2023-40430
was published
Jan 11, 2024
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Low
CVE-2024-30260
was published
for
undici
(npm)
Apr 4, 2024
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in...
High
Unreviewed
CVE-2024-40814
was published
Jul 30, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21166
was published
Jul 17, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21179
was published
Jul 17, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21159
was published
Jul 17, 2024
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight...
High
Unreviewed
CVE-2023-47166
was published
May 1, 2024
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS...
Moderate
Unreviewed
CVE-2024-40807
was published
Jul 30, 2024
The issue was addressed with improved restriction of data container access. This issue is fixed...
High
Unreviewed
CVE-2024-40783
was published
Jul 30, 2024
ProTip!
Advisories are also available from the
GraphQL API