GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,890
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,215
NuGet
744
pip
3,991
Pub
12
RubyGems
950
Rust
1,038
Swift
45
Unreviewed advisories
All unreviewed
5,000+
732 advisories
Filter by severity
Better Auth: Unauthenticated API key creation through api-key plugin
Critical
GHSA-99h5-pjcv-gr6v
was published
for
better-auth
(npm)
Oct 9, 2025
An issue in the permission verification module and organization/application editing interface in...
High
Unreviewed
CVE-2025-61524
was published
Oct 8, 2025
XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
Critical
CVE-2025-49594
was published
for
org.xwiki.contrib.oidc:oidc-authenticator
(Maven)
Oct 6, 2025
A vulnerability was detected in zhuimengshaonian wisdom-education up to 1.0.4. The affected...
Moderate
Unreviewed
CVE-2025-11321
was published
Oct 6, 2025
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-11227
was published
Oct 4, 2025
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
Low
GHSA-q6hv-wcjr-wp8h
was published
for
github.com/kcp-dev/kcp
(Go)
Sep 26, 2025
A flaw has been found in Sistemas Pleno Gestão de Locação up to 2025.7.x. The impacted element is...
Moderate
Unreviewed
CVE-2025-10947
was published
Sep 25, 2025
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317...
High
Unreviewed
CVE-2025-59305
was published
Sep 24, 2025
A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of...
Moderate
Unreviewed
CVE-2025-10759
was published
Sep 22, 2025
Authorization Bypass Through User-Controlled Key, CWE - 862 - Missing Authorization, – Improper...
Moderate
Unreviewed
CVE-2025-8532
was published
Sep 19, 2025
Authorization Bypass Through User-Controlled Key, Externally Controlled Reference to a Resource...
Moderate
Unreviewed
CVE-2025-8057
was published
Sep 16, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8. An...
Moderate
Unreviewed
CVE-2025-43231
was published
Sep 16, 2025
An authorization issue was addressed with improved state management. This issue is fixed in tvOS...
Critical
Unreviewed
CVE-2025-31255
was published
Sep 16, 2025
In version 0.7.8 of danny-avila/librechat, improper authorization controls in the conversation...
Moderate
Unreviewed
CVE-2025-6088
was published
Sep 11, 2025
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due...
High
Unreviewed
CVE-2025-26430
was published
Sep 5, 2025
A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function...
Moderate
Unreviewed
CVE-2025-9835
was published
Sep 3, 2025
A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function...
Moderate
Unreviewed
CVE-2025-9836
was published
Sep 3, 2025
The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to...
Moderate
Unreviewed
CVE-2025-8147
was published
Aug 29, 2025
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2025-53795
was published
Aug 21, 2025
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-7221
was published
Aug 21, 2025
The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to...
Critical
Unreviewed
CVE-2025-7778
was published
Aug 15, 2025
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
Moderate
CVE-2025-55675
was published
for
apache-superset
(pip)
Aug 14, 2025
A vulnerability, which was classified as problematic, has been found in LitmusChaos Litmus up to...
Moderate
Unreviewed
CVE-2025-8794
was published
Aug 10, 2025
A vulnerability was found in Portabilis i-Educar up to 2.9.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-8789
was published
Aug 10, 2025
ProTip!
Advisories are also available from the
GraphQL API