GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
120 advisories
Filter by severity
GraphQL query operations security can be bypassed
High
CVE-2025-31481
was published
for
api-platform/core
(Composer)
Apr 4, 2025
Drupal Commerce Alphabank Redirect Incorrect Authorization vulnerability
High
CVE-2025-48446
was published
for
drupal/commerce_alphabank_redirect
(Composer)
Jun 11, 2025
Drupal Commerce Eurobank (Redirect) Incorrect Authorization vulnerability
High
CVE-2025-48445
was published
for
drupal/commerce_eurobank_redirect
(Composer)
Jun 11, 2025
MantisBT Incorrect Authorization in bug_actiongroup_page.php
Moderate
CVE-2020-29605
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
MantisBT Incorrect Authorization for bug_revision_view_page.php check
High
CVE-2020-35849
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
MantisBT unauthorized users able to access private files
Moderate
CVE-2020-25781
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
TYPO3 Allows Information Disclosure via DBAL Restriction Handling
Low
CVE-2025-47937
was published
for
typo3/cms-core
(Composer)
May 20, 2025
Moodle Incorrect Authorization vulnerability
High
CVE-2020-14321
was published
for
moodle/moodle
(Composer)
Aug 17, 2022
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing
High
CVE-2025-31694
was published
for
drupal/tfa
(Composer)
Apr 1, 2025
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
Critical
CVE-2022-47408
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24436
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24437
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Moodle does not properly restrict comment capabilities
Moderate
CVE-2011-4297
was published
for
moodle/moodle
(Composer)
May 13, 2022
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
Adobe Commerce Improper Authorization vulnerability
High
CVE-2025-24409
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-38218
was published
for
magento/community-edition
(Composer)
Oct 13, 2023
Magento Open Source allows Incorrect Authorization
Low
CVE-2023-29296
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-38209
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source allows Incorrect Authorization
Low
CVE-2023-29295
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
ProTip!
Advisories are also available from the
GraphQL API