GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,780 advisories
Filter by severity
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for...
Moderate
Unreviewed
CVE-2025-9376
was published
Aug 28, 2025
An authentication issue was addressed with improved state management. This issue is fixed in...
High
Unreviewed
CVE-2025-24206
was published
Apr 29, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
An incorrect authorization vulnerability allowed unauthorized read access to the contents of...
Moderate
Unreviewed
CVE-2025-6981
was published
Jul 15, 2025
An access control vulnerability was discovered in the Request Trace and Download Trace...
Moderate
Unreviewed
CVE-2025-1501
was published
Aug 26, 2025
IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004...
Critical
Unreviewed
CVE-2025-36157
was published
Aug 24, 2025
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege...
High
Unreviewed
CVE-2017-3891
was published
May 13, 2022
An Improper Access Control could allow a malicious actor authenticated in the API of certain...
Moderate
Unreviewed
CVE-2025-27213
was published
Aug 21, 2025
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to...
Moderate
Unreviewed
CVE-2025-57728
was published
Aug 20, 2025
MiR software versions prior to version 3.0.0 have insufficient authorization controls when...
Moderate
Unreviewed
CVE-2025-9228
was published
Aug 20, 2025
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their...
High
Unreviewed
CVE-2025-36120
was published
Aug 18, 2025
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web...
High
Unreviewed
CVE-2025-7773
was published
Aug 14, 2025
Capsule tenant owner with "patch namespace" permission can hijack system namespaces
High
CVE-2024-39690
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 20, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1...
Moderate
Unreviewed
CVE-2024-10219
was published
Aug 13, 2025
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and...
High
Unreviewed
CVE-2025-49556
was published
Aug 12, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
High
Unreviewed
CVE-2024-41979
was published
Aug 12, 2025
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain...
High
Unreviewed
CVE-2025-42951
was published
Aug 12, 2025
@fedify/fedify has Improper Authentication and Incorrect Authorization
High
CVE-2025-54888
was published
for
@fedify/fedify
(npm)
Aug 8, 2025
Certain MQTT wildcards are not blocked on the
CyberPower PowerPanel
system, which might result...
Moderate
Unreviewed
CVE-2024-31409
was published
May 15, 2024
A vulnerability was identified in the XPC services of Fantastical. The services failed to...
Moderate
Unreviewed
CVE-2025-8533
was published
Aug 7, 2025
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated,...
Moderate
Unreviewed
CVE-2025-20332
was published
Aug 6, 2025
tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that...
Moderate
Unreviewed
CVE-2025-54554
was published
Aug 5, 2025
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without...
High
Unreviewed
CVE-2025-20701
was published
Aug 4, 2025
GitProxy Approval Bypass When Pushing Multiple Branches
High
CVE-2025-54583
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API