GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,300 advisories
Filter by severity
Mattermost allows unauthorized channel member management through playbook runs
Moderate
CVE-2025-3227
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Mattermost allows an unauthorized Guest user access to Playbook
Moderate
CVE-2025-3228
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 20, 2025
Yealink YMCS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts,...
Moderate
Unreviewed
CVE-2025-52918
was published
Jun 22, 2025
An incorrect authorization vulnerability exists in multiple WSO2 products that allows...
Moderate
Unreviewed
CVE-2024-3511
was published
Jun 23, 2025
Under certain conditions, an authenticated user request may execute with stale privileges...
Moderate
Unreviewed
CVE-2025-6707
was published
Jun 26, 2025
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0....
Moderate
Unreviewed
CVE-2025-6702
was published
Jun 26, 2025
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected...
Moderate
Unreviewed
CVE-2025-49550
was published
Jun 26, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-47871
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 30, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-46702
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 30, 2025
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2025-20300
was published
Jul 7, 2025
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025...
Moderate
Unreviewed
CVE-2025-20999
was published
Jul 8, 2025
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0...
Moderate
Unreviewed
CVE-2025-3396
was published
Jul 10, 2025
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX...
Moderate
Unreviewed
CVE-2025-6549
was published
Jul 11, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30747
was published
Jul 15, 2025
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2025-30739
was published
Jul 15, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30748
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-50084
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Moderate
Unreviewed
CVE-2025-50086
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-50085
was published
Jul 15, 2025
An incorrect authorization vulnerability allowed unauthorized read access to the contents of...
Moderate
Unreviewed
CVE-2025-6981
was published
Jul 15, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1...
Moderate
Unreviewed
CVE-2025-0765
was published
Jul 25, 2025
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the...
Moderate
Unreviewed
CVE-2025-54596
was published
Jul 25, 2025
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to...
Moderate
Unreviewed
CVE-2025-54569
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54532
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54533
was published
Jul 28, 2025
ProTip!
Advisories are also available from the
GraphQL API