GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,829
Erlang
36
GitHub Actions
33
Go
2,446
Maven
5,000+
npm
4,065
NuGet
723
pip
3,866
Pub
12
RubyGems
943
Rust
1,009
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,751 advisories
Filter by severity
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web...
High
Unreviewed
CVE-2025-7773
was published
Aug 14, 2025
Capsule tenant owner with "patch namespace" permission can hijack system namespaces
High
CVE-2024-39690
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 20, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1...
Moderate
Unreviewed
CVE-2024-10219
was published
Aug 13, 2025
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and...
High
Unreviewed
CVE-2025-49556
was published
Aug 12, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
High
Unreviewed
CVE-2024-41979
was published
Aug 12, 2025
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain...
High
Unreviewed
CVE-2025-42951
was published
Aug 12, 2025
@fedify/fedify has Improper Authentication and Incorrect Authorization
High
CVE-2025-54888
was published
for
@fedify/fedify
(npm)
Aug 8, 2025
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
Critical
CVE-2024-38002
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Certain MQTT wildcards are not blocked on the
CyberPower PowerPanel
system, which might result...
Moderate
Unreviewed
CVE-2024-31409
was published
May 15, 2024
A vulnerability was identified in the XPC services of Fantastical. The services failed to...
Moderate
Unreviewed
CVE-2025-8533
was published
Aug 7, 2025
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated,...
Moderate
Unreviewed
CVE-2025-20332
was published
Aug 6, 2025
tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that...
Moderate
Unreviewed
CVE-2025-54554
was published
Aug 5, 2025
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without...
High
Unreviewed
CVE-2025-20701
was published
Aug 4, 2025
GitProxy Approval Bypass When Pushing Multiple Branches
High
CVE-2025-54583
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43251
was published
Jul 30, 2025
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2025-8068
was published
Jul 31, 2025
The issue was addressed with additional permissions checks. This issue is fixed in iPadOS 17.7.9,...
Moderate
Unreviewed
CVE-2025-43230
was published
Jul 30, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-43197
was published
Jul 30, 2025
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54533
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54532
was published
Jul 28, 2025
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to...
Moderate
Unreviewed
CVE-2025-54569
was published
Jul 28, 2025
ProTip!
Advisories are also available from the
GraphQL API