GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
384 advisories
Filter by severity
Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module....
High
Unreviewed
CVE-2023-52359
was published
Apr 8, 2024
Due to insufficient server-side validation, a successful exploit of this vulnerability could...
High
Unreviewed
CVE-2024-25063
was published
Mar 2, 2024
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Managing Settings and...
High
Unreviewed
CVE-2025-30117
was published
Mar 18, 2025
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
High
CVE-2023-50780
was published
for
org.apache.activemq:artemis-cli
(Maven)
Oct 14, 2024
Adobe Commerce Improper Authorization vulnerability
High
CVE-2025-24409
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to...
High
Unreviewed
CVE-2024-2441
was published
May 14, 2024
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-24053
was published
Mar 13, 2025
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information...
High
Unreviewed
CVE-2025-1361
was published
Feb 22, 2025
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows...
High
Unreviewed
CVE-2022-3787
was published
Mar 29, 2023
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in...
High
Unreviewed
CVE-2024-7624
was published
Aug 15, 2024
Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
High
CVE-2024-53949
was published
for
apache-superset
(pip)
Dec 9, 2024
Microsoft SharePoint Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-21400
was published
Feb 11, 2025
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are...
High
Unreviewed
CVE-2025-24418
was published
Feb 11, 2025
Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
High
CVE-2024-55633
was published
for
apache-superset
(pip)
Dec 12, 2024
Contrast's unauthenticated recovery allows Coordinator impersonation
High
GHSA-vqv5-385r-2hf8
was published
for
github.com/edgelesssys/contrast
(Go)
Feb 5, 2025
MarbleRun unauthenticated recovery allows Coordinator impersonation
High
GHSA-w7wm-2425-7p2h
was published
for
github.com/edgelesssys/marblerun
(Go)
Feb 4, 2025
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features)...
High
Unreviewed
CVE-2024-13694
was published
Jan 30, 2025
The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that...
High
Unreviewed
CVE-2024-13646
was published
Jan 30, 2025
XWiki users registered with email verification can self re-activate their disabled accounts
High
CVE-2021-32620
was published
for
org.xwiki.commons:xwiki-commons-core
(Maven)
May 18, 2021
Gradios's CORS origin validation is not performed when the request has a cookie
High
CVE-2024-47084
was published
for
gradio
(pip)
Oct 10, 2024
Microsoft SharePoint Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-21348
was published
Jan 14, 2025
Windows App Package Installer Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21275
was published
Jan 14, 2025
Potential Vulnerabilities Due to Outdated golang.org/x/crypto Dependency in NanoProxy
High
GHSA-7prj-hgx4-2xc3
was published
for
github.com/ryanbekhen/nanoproxy
(Go)
Dec 12, 2024
Harbor fails to validate the user permissions when updating p2p preheat policies
High
CVE-2022-31668
was published
for
github.com/goharbor/harbor
(Go)
Nov 14, 2024
An authenticated user with API access (e.g.: user with default User role), more specifically a...
High
Unreviewed
CVE-2024-36467
was published
Nov 27, 2024
ProTip!
Advisories are also available from the
GraphQL API