GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,299 advisories
Filter by severity
Deno run with --allow-read and --deny-read flags results in allowed
Moderate
CVE-2025-48888
was published
for
deno
(Rust)
Jun 4, 2025
Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Moderate
CVE-2025-48935
was published
for
deno
(Rust)
Jun 4, 2025
The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization /...
Moderate
Unreviewed
CVE-2022-40843
was published
Nov 15, 2022
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform...
Moderate
Unreviewed
CVE-2025-20300
was published
Jul 7, 2025
A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0....
Moderate
Unreviewed
CVE-2025-6702
was published
Jun 26, 2025
An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0...
Moderate
Unreviewed
CVE-2025-3396
was published
Jul 10, 2025
An Incorrect Authorization vulnerability in the web server of Juniper Networks Junos OS on SRX...
Moderate
Unreviewed
CVE-2025-6549
was published
Jul 11, 2025
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025...
Moderate
Unreviewed
CVE-2025-20999
was published
Jul 8, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30748
was published
Jul 15, 2025
Apache Superset Allows Ownership Takeover
Moderate
CVE-2025-27696
was published
for
apache-superset
(pip)
May 13, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30747
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-50084
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Moderate
Unreviewed
CVE-2025-50086
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-50085
was published
Jul 15, 2025
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2025-30739
was published
Jul 15, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1...
Moderate
Unreviewed
CVE-2025-0765
was published
Jul 25, 2025
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the...
Moderate
Unreviewed
CVE-2025-54596
was published
Jul 25, 2025
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
Moderate
Unreviewed
CVE-2024-6150
was published
Jul 10, 2024
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to...
Moderate
Unreviewed
CVE-2025-54569
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54532
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54533
was published
Jul 28, 2025
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-43197
was published
Jul 30, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API