GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,966
NuGet
713
pip
3,759
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
115 advisories
Filter by severity
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58125
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58127
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58124
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58126
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2025-31170
was published
Apr 7, 2025
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this...
High
Unreviewed
CVE-2025-2188
was published
Apr 17, 2025
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by...
High
Unreviewed
CVE-2017-8422
was published
May 13, 2022
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in...
High
Unreviewed
CVE-2025-29621
was published
Apr 22, 2025
An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP...
High
Unreviewed
CVE-2025-28128
was published
Apr 25, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Attribute Smuggling
High
CVE-2025-46573
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an...
High
Unreviewed
CVE-2025-3875
was published
May 14, 2025
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
GitLab auth uses full name instead of username as user ID, allowing impersonation
High
CVE-2020-5415
was published
for
github.com/concourse/concourse
(Go)
Dec 20, 2021
Authentication bypass vulnerability in the DSoftBus module
Impact: Successful exploitation of...
High
Unreviewed
CVE-2025-48906
was published
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API