GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,473
Maven
5,000+
npm
4,091
NuGet
734
pip
3,907
Pub
12
RubyGems
944
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,292 advisories
Filter by severity
Incorrect authorization in Kibana can lead to privilege escalation via the built-in...
Moderate
Unreviewed
CVE-2025-25010
was published
Aug 28, 2025
The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for...
Moderate
Unreviewed
CVE-2025-9376
was published
Aug 28, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference
Moderate
CVE-2025-5187
was published
for
k8s.io/kubernetes
(Go)
Aug 27, 2025
An incorrect authorization vulnerability allowed unauthorized read access to the contents of...
Moderate
Unreviewed
CVE-2025-6981
was published
Jul 15, 2025
An access control vulnerability was discovered in the Request Trace and Download Trace...
Moderate
Unreviewed
CVE-2025-1501
was published
Aug 26, 2025
An Improper Access Control could allow a malicious actor authenticated in the API of certain...
Moderate
Unreviewed
CVE-2025-27213
was published
Aug 21, 2025
In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to...
Moderate
Unreviewed
CVE-2025-57728
was published
Aug 20, 2025
MiR software versions prior to version 3.0.0 have insufficient authorization controls when...
Moderate
Unreviewed
CVE-2025-9228
was published
Aug 20, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-55213
was published
for
github.com/openfga/openfga
(Go)
Aug 18, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1...
Moderate
Unreviewed
CVE-2024-10219
was published
Aug 13, 2025
Certain MQTT wildcards are not blocked on the
CyberPower PowerPanel
system, which might result...
Moderate
Unreviewed
CVE-2024-31409
was published
May 15, 2024
A vulnerability was identified in the XPC services of Fantastical. The services failed to...
Moderate
Unreviewed
CVE-2025-8533
was published
Aug 7, 2025
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated,...
Moderate
Unreviewed
CVE-2025-20332
was published
Aug 6, 2025
tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that...
Moderate
Unreviewed
CVE-2025-54554
was published
Aug 5, 2025
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43251
was published
Jul 30, 2025
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized...
Moderate
Unreviewed
CVE-2025-8068
was published
Jul 31, 2025
The issue was addressed with additional permissions checks. This issue is fixed in iPadOS 17.7.9,...
Moderate
Unreviewed
CVE-2025-43230
was published
Jul 30, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-43197
was published
Jul 30, 2025
Liferay Portal and Liferay DXP Allows Authenticated Users with View Permissions to Edit Permissions
Moderate
CVE-2024-25604
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
Liferay Portal and Liferay DXP Does Not Properly Restrict Membership to Child Site Based on Parent Site Options
Moderate
CVE-2024-25149
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54533
was published
Jul 28, 2025
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings...
Moderate
Unreviewed
CVE-2025-54532
was published
Jul 28, 2025
In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to...
Moderate
Unreviewed
CVE-2025-54569
was published
Jul 28, 2025
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
Moderate
Unreviewed
CVE-2024-6150
was published
Jul 10, 2024
ProTip!
Advisories are also available from the
GraphQL API