GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,499
Maven
5,000+
npm
4,138
NuGet
735
pip
3,945
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,782 advisories
Filter by severity
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14...
High
Unreviewed
CVE-2024-44305
was published
Mar 21, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
Moderate
CVE-2025-24920
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels
Moderate
CVE-2025-25274
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Enforce Certain Search APIs
Moderate
CVE-2025-30179
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public
Moderate
CVE-2025-27933
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 21, 2025
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
Low
CVE-2025-27715
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Authorization Bypass in Next.js Middleware
Critical
CVE-2025-29927
was published
for
next
(npm)
Mar 21, 2025
Cilium East-west traffic not subject to egress policy enforcement for requests via Gateway API load balancers
Low
CVE-2025-30162
was published
for
github.com/cilium/cilium
(Go)
Mar 24, 2025
Cilium node based network policies may incorrectly allow workload traffic
Low
CVE-2025-30163
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Mar 24, 2025
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an...
Critical
Unreviewed
CVE-2025-1542
was published
Mar 26, 2025
An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have...
Moderate
Unreviewed
CVE-2024-55965
was published
Mar 26, 2025
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior...
High
Unreviewed
CVE-2025-2242
was published
Mar 27, 2025
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before...
High
Unreviewed
CVE-2025-30093
was published
Mar 27, 2025
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing
High
CVE-2025-31694
was published
for
drupal/tfa
(Composer)
Apr 1, 2025
This issue was addressed with improved data access restriction. This issue is fixed in visionOS 2...
High
Unreviewed
CVE-2025-24221
was published
Apr 1, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Critical
Unreviewed
CVE-2025-24233
was published
Apr 1, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and...
Low
Unreviewed
CVE-2025-30469
was published
Apr 1, 2025
Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
Low
CVE-2025-27427
was published
for
org.apache.activemq:artemis-server
(Maven)
Apr 1, 2025
Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of...
Critical
Unreviewed
CVE-2024-38392
was published
Apr 2, 2025
GraphQL query operations security can be bypassed
High
CVE-2025-31481
was published
for
api-platform/core
(Composer)
Apr 4, 2025
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions...
Moderate
Unreviewed
CVE-2025-31331
was published
Apr 8, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
GHSA-6jrf-4jv4-r9mw
was published
for
tendermint-light-client-verifier
(Rust)
Apr 9, 2025
ProTip!
Advisories are also available from the
GraphQL API