GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
384 advisories
Filter by severity
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
High
CVE-2026-22033
was published
for
label-studio
(pip)
Jan 12, 2026
Finality Provider vulnerable to anti-slashing bypassing due to misconfiguration
High
GHSA-4jmp-x7mh-rgmr
was published
for
github.com/babylonlabs-io/finality-provider
(Go)
Dec 12, 2025
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The...
High
Unreviewed
CVE-2025-40830
was published
Dec 9, 2025
Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
High
CVE-2025-66301
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
OneUptime Unauthorized User Creation via API
High
CVE-2025-65966
was published
for
@oneuptime/common
(npm)
Nov 26, 2025
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary...
High
Unreviewed
CVE-2025-64065
was published
Nov 25, 2025
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but...
High
Unreviewed
CVE-2025-64062
was published
Nov 25, 2025
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized...
High
Unreviewed
CVE-2025-64655
was published
Nov 21, 2025
File Browser is Vulnerable to Insecure Direct Object Reference (IDOR) in Share Deletion Function
High
CVE-2025-64523
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Nov 13, 2025
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-11521
was published
Nov 11, 2025
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is...
High
Unreviewed
CVE-2025-4519
was published
Nov 7, 2025
Hono Improper Authorization vulnerability
High
CVE-2025-62610
was published
for
hono
(npm)
Oct 22, 2025
Redis Enterprise Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-59271
was published
Oct 9, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
High
CVE-2025-61928
was published
for
better-auth
(npm)
Oct 9, 2025
Casdoor is vulnerable to Improper Authorization
High
CVE-2025-61524
was published
for
github.com/casdoor/casdoor
(Go)
Oct 8, 2025
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317...
High
Unreviewed
CVE-2025-59305
was published
Sep 24, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due...
High
Unreviewed
CVE-2025-26430
was published
Sep 5, 2025
GitProxy New Branch Approval Exploit
High
CVE-2025-54585
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
HAX CMS API Lacks Authorization Checks
High
CVE-2025-54378
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 25, 2025
The Application is vulnerable to an Unauthenticated Arbitrary File Read. This affects the
Agent...
High
Unreviewed
CVE-2024-26291
was published
Jul 14, 2025
Juju allows arbitrary executable uploads via authenticated endpoint without authorization
High
CVE-2025-0928
was published
for
github.com/juju/juju
(Go)
Jul 9, 2025
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute...
High
Unreviewed
CVE-2025-49701
was published
Jul 8, 2025
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without...
High
Unreviewed
CVE-2025-6713
was published
Jul 7, 2025
Graylog vulnerable to privilege escalation through API tokens
High
CVE-2025-53106
was published
for
org.graylog2:graylog2-server
(Maven)
Jun 30, 2025
ProTip!
Advisories are also available from the
GraphQL API