Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

732 advisories

Loading
Better Auth: Unauthenticated API key creation through api-key plugin Critical
GHSA-99h5-pjcv-gr6v was published for better-auth (npm) Oct 9, 2025
etiennelunetta
Credited to etiennelunetta
XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view Critical
CVE-2025-49594 was published for org.xwiki.contrib.oidc:oidc-authenticator (Maven) Oct 6, 2025
SimonTheLeg embik
Credited to SimonTheLeg and embik
Spring Framework annotation detection mechanism may result in improper authorization High
CVE-2025-41249 was published for org.springframework:spring-core (Maven) Sep 16, 2025
The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to... Critical Unreviewed
CVE-2025-7778 was published Aug 15, 2025
ProTip! Advisories are also available from the GraphQL API