GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,779 advisories
Filter by severity
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2025-8068
was published
Jul 31, 2025
The issue was addressed with additional permissions checks. This issue is fixed in iPadOS 17.7.9,...
Moderate
Unreviewed
CVE-2025-43230
was published
Jul 30, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-43197
was published
Jul 30, 2025
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54532
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54533
was published
Jul 28, 2025
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to...
Moderate
Unreviewed
CVE-2025-54569
was published
Jul 28, 2025
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
Moderate
Unreviewed
CVE-2024-6150
was published
Jul 10, 2024
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the...
Moderate
Unreviewed
CVE-2025-54596
was published
Jul 25, 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the...
Low
Unreviewed
CVE-2025-32462
was published
Jun 30, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1...
Moderate
Unreviewed
CVE-2025-0765
was published
Jul 25, 2025
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux...
High
Unreviewed
CVE-2025-6018
was published
Jul 23, 2025
Cryptographic issue occurs due to use of insecure connection method while downloading.
Critical
Unreviewed
CVE-2025-21450
was published
Jul 8, 2025
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud...
Critical
Unreviewed
CVE-2025-29757
was published
Jul 19, 2025
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2025-30739
was published
Jul 15, 2025
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite ...
High
Unreviewed
CVE-2025-30743
was published
Jul 15, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30747
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-50084
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Moderate
Unreviewed
CVE-2025-50086
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-50085
was published
Jul 15, 2025
Apache Superset Allows Ownership Takeover
Moderate
CVE-2025-27696
was published
for
apache-superset
(pip)
May 13, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30748
was published
Jul 15, 2025
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that...
Low
Unreviewed
CVE-2025-30750
was published
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API