GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
174 advisories
Filter by severity
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP...
Moderate
Unreviewed
CVE-2025-52621
was published
Aug 16, 2025
In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic...
Moderate
Unreviewed
CVE-2025-53399
was published
Aug 1, 2025
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
Moderate
GHSA-gj52-35xm-gxjh
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
•
withdrawn
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass...
Moderate
Unreviewed
CVE-2025-5824
was published
Jun 26, 2025
The security settings in the SAP Business One Integration Framework are not adequately checked,...
Moderate
Unreviewed
CVE-2025-42998
was published
Jun 10, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Moderate
CVE-2025-30360
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
Error handling for script execution was incorrectly isolated from web content, which could have...
Moderate
Unreviewed
CVE-2025-5263
was published
May 27, 2025
A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2....
Moderate
Unreviewed
CVE-2025-4515
was published
May 10, 2025
@misskey-dev/summaly allows IP Filter Bypass via Redirect
Moderate
GHSA-jqx4-9gpq-rppm
was published
for
@misskey-dev/summaly
(npm)
May 6, 2025
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local...
Moderate
Unreviewed
CVE-2025-43929
was published
Apr 20, 2025
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a...
Moderate
Unreviewed
CVE-2025-3071
was published
Apr 2, 2025
An intent redriction vulnerability exists in the Xiaomi quick App framework application product....
Moderate
Unreviewed
CVE-2024-45353
was published
Mar 27, 2025
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is...
Moderate
Unreviewed
CVE-2024-45354
was published
Mar 27, 2025
An Insufficient Firmware Update Validation vulnerability could allow an authenticated malicious...
Moderate
Unreviewed
CVE-2025-23117
was published
Mar 1, 2025
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or...
Moderate
Unreviewed
CVE-2025-1102
was published
Feb 12, 2025
esbuild enables any website to send any requests to the development server and read the response
Moderate
GHSA-67mh-4wv8-2f99
was published
for
esbuild
(npm)
Feb 10, 2025
Vulnerability in the Oracle Communications Order and Service Management product of Oracle...
Moderate
Unreviewed
CVE-2025-21542
was published
Jan 21, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-21497
was published
Jan 21, 2025
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component:...
Moderate
Unreviewed
CVE-2024-21245
was published
Jan 21, 2025
Websites were able to send any requests to the development server and read the response in vite
Moderate
CVE-2025-24010
was published
for
vite
(npm)
Jan 21, 2025
A ZigBee coordinator, router, or end device may change their node ID when an unsolicited...
Moderate
Unreviewed
CVE-2024-7322
was published
Jan 15, 2025
An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0...
Moderate
Unreviewed
CVE-2023-46715
was published
Jan 14, 2025
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the...
Moderate
Unreviewed
CVE-2025-23109
was published
Jan 11, 2025
ProTip!
Advisories are also available from the
GraphQL API