GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,746 advisories
Filter by severity
@fedify/fedify has Improper Authentication and Incorrect Authorization
High
CVE-2025-54888
was published
for
@fedify/fedify
(npm)
Aug 8, 2025
A vulnerability was identified in the XPC services of Fantastical. The services failed to...
Moderate
Unreviewed
CVE-2025-8533
was published
Aug 7, 2025
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated,...
Moderate
Unreviewed
CVE-2025-20332
was published
Aug 6, 2025
tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that...
Moderate
Unreviewed
CVE-2025-54554
was published
Aug 5, 2025
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without...
High
Unreviewed
CVE-2025-20701
was published
Aug 4, 2025
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2025-8068
was published
Jul 31, 2025
GitProxy Approval Bypass When Pushing Multiple Branches
High
CVE-2025-54583
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43251
was published
Jul 30, 2025
The issue was addressed with additional permissions checks. This issue is fixed in iPadOS 17.7.9,...
Moderate
Unreviewed
CVE-2025-43230
was published
Jul 30, 2025
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-43197
was published
Jul 30, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54533
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54532
was published
Jul 28, 2025
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to...
Moderate
Unreviewed
CVE-2025-54569
was published
Jul 28, 2025
Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the...
Moderate
Unreviewed
CVE-2025-54596
was published
Jul 25, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1...
Moderate
Unreviewed
CVE-2025-0765
was published
Jul 25, 2025
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux...
High
Unreviewed
CVE-2025-6018
was published
Jul 23, 2025
An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud...
Critical
Unreviewed
CVE-2025-29757
was published
Jul 19, 2025
An incorrect authorization vulnerability allowed unauthorized read access to the contents of...
Moderate
Unreviewed
CVE-2025-6981
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-50085
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2025-50084
was published
Jul 15, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services...
Moderate
Unreviewed
CVE-2025-50086
was published
Jul 15, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
Moderate
Unreviewed
CVE-2025-30748
was published
Jul 15, 2025
Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions...
High
Unreviewed
CVE-2025-30751
was published
Jul 15, 2025
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component:...
High
Unreviewed
CVE-2025-30744
was published
Jul 15, 2025
ProTip!
Advisories are also available from the
GraphQL API