GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,800
Erlang
36
GitHub Actions
29
Go
2,380
Maven
5,000+
npm
4,005
NuGet
720
pip
3,805
Pub
12
RubyGems
927
Rust
986
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,260 advisories
Filter by severity
A low-privileged user can access information about profiles created in Proget MDM (Mobile Device...
Moderate
Unreviewed
CVE-2025-1418
was published
May 21, 2025
In Proget MDM, a low-privileged user can access information about changes contained in backups of...
Moderate
Unreviewed
CVE-2025-1417
was published
May 21, 2025
The MultiVendorX – WooCommerce Multivendor Marketplace Solutions plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-4101
was published
May 17, 2025
Mattermost Fails to Verify User's Permissions When Accessing Groups
Moderate
CVE-2025-2527
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 15, 2025
Mattermost Fails to Validate Team Invite Permissions
Moderate
CVE-2025-3446
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 15, 2025
OpenCanary Executes Commands From Potentially Writable Config File
Moderate
CVE-2024-48911
was published
for
OpenCanary
(pip)
Oct 14, 2024
IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive...
Moderate
Unreviewed
CVE-2022-38388
was published
Oct 11, 2022
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5...
Moderate
Unreviewed
CVE-2025-31227
was published
May 13, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS...
Moderate
Unreviewed
CVE-2025-30440
was published
May 13, 2025
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager.
The vulnerability...
Moderate
Unreviewed
CVE-2025-3272
was published
May 7, 2025
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android...
Moderate
Unreviewed
CVE-2022-41797
was published
Oct 24, 2022
A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as...
Moderate
Unreviewed
CVE-2024-2557
was published
Mar 17, 2024
Hashicorp Vault Community vulnerable to Incorrect Authorization
Moderate
CVE-2025-3879
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all...
Moderate
Unreviewed
CVE-2025-3609
was published
May 6, 2025
A permissions issue existed. This issue was addressed with improved permission validation. This...
Moderate
Unreviewed
CVE-2022-42788
was published
Nov 2, 2022
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user...
Moderate
Unreviewed
CVE-2021-0124
was published
Feb 11, 2022
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from...
Moderate
Unreviewed
CVE-2022-3413
was published
Nov 10, 2022
OpenFGA Authorization Bypass
Moderate
CVE-2025-46331
was published
for
github.com/openfga/openfga
(Go)
Apr 30, 2025
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating...
Moderate
Unreviewed
CVE-2021-25920
was published
May 24, 2022
A vulnerability in the access control list (ACL) programming for port channel subinterfaces of...
Moderate
Unreviewed
CVE-2024-20291
was published
Feb 29, 2024
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create...
Moderate
Unreviewed
CVE-2025-43921
was published
Apr 20, 2025
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
ProTip!
Advisories are also available from the
GraphQL API