GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,667
Maven
5,000+
npm
4,295
NuGet
760
pip
4,073
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
989 advisories
Filter by severity
Authorization Bypass Through User-Controlled Key vulnerability in Sayful Islam Upcoming Events...
Moderate
Unreviewed
CVE-2025-57994
was published
Sep 22, 2025
Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software...
Moderate
Unreviewed
CVE-2025-0875
was published
Sep 22, 2025
Mattermost boards plugin fails to restrict download access to files
Low
CVE-2025-9081
was published
for
github.com/mattermost/mattermost-plugin-boards
(Go)
Sep 19, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Tronclass developed by WisdomGarden has an Insecure Direct object Reference vulnerability,...
Moderate
Unreviewed
CVE-2025-10719
was published
Sep 19, 2025
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via...
Critical
Unreviewed
CVE-2025-5948
was published
Sep 19, 2025
The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
Moderate
Unreviewed
CVE-2025-10493
was published
Sep 18, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Nebula Informatics SecHard...
Moderate
Unreviewed
CVE-2025-8463
was published
Sep 17, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Beefull Energy Technologies...
Moderate
Unreviewed
CVE-2025-7355
was published
Sep 16, 2025
Authorization Bypass Through User-Controlled Key vulnerability with user privileges in ArgusTech...
Moderate
Unreviewed
CVE-2025-5518
was published
Sep 16, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Liferay Portal is vulnerable to Insecure Direct Object Reference (IDOR) attack through Authentication Bypass
High
CVE-2025-43790
was published
for
com.liferay:com.liferay.object.service
(Maven)
Sep 11, 2025
Indico may disclose unauthorized user details access via legacy API
Moderate
CVE-2025-59034
was published
for
indico
(pip)
Sep 10, 2025
The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2025-7718
was published
Sep 10, 2025
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege...
High
Unreviewed
CVE-2025-7049
was published
Sep 10, 2025
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to...
Critical
Unreviewed
CVE-2025-9114
was published
Sep 8, 2025
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4...
High
Unreviewed
CVE-2025-52389
was published
Sep 8, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum allows...
Moderate
Unreviewed
CVE-2025-58597
was published
Sep 3, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows...
Moderate
Unreviewed
CVE-2025-0670
was published
Sep 2, 2025
PHPGurukul Employee Leave Management System 2.1 contains an Insecure Direct Object Reference ...
Moderate
Unreviewed
CVE-2025-56254
was published
Sep 2, 2025
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed...
High
Unreviewed
CVE-2025-8447
was published
Aug 26, 2025
An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash...
Critical
Unreviewed
CVE-2025-45968
was published
Aug 25, 2025
An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows...
Moderate
Unreviewed
CVE-2025-55621
was published
Aug 22, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility...
Moderate
Unreviewed
CVE-2025-57886
was published
Aug 22, 2025
Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5...
High
Unreviewed
CVE-2025-55370
was published
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API