GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
370 advisories
Filter by severity
Babylon Finality Provider `MsgCommitPubRandList` replay attack
High
GHSA-7mm3-vfg8-7rg6
was published
for
github.com/babylonlabs-io/babylon
(Go)
May 15, 2025
The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary...
Moderate
Unreviewed
CVE-2025-48027
was published
May 15, 2025
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an...
High
Unreviewed
CVE-2025-3875
was published
May 14, 2025
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to...
Moderate
Unreviewed
CVE-2025-3909
was published
May 14, 2025
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by...
Moderate
Unreviewed
CVE-2025-27695
was published
May 8, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Attribute Smuggling
High
CVE-2025-46573
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
An app could impersonate system notifications. Sensitive notifications now require restricted...
Moderate
Unreviewed
CVE-2025-24091
was published
Apr 30, 2025
An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP...
High
Unreviewed
CVE-2025-28128
was published
Apr 25, 2025
Francois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in...
High
Unreviewed
CVE-2025-29621
was published
Apr 22, 2025
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Moderate
CVE-2025-32788
was published
for
octoprint
(pip)
Apr 22, 2025
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this...
High
Unreviewed
CVE-2025-2188
was published
Apr 17, 2025
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system...
Moderate
Unreviewed
CVE-2023-5616
was published
Apr 15, 2025
Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker allows Identity Spoofing....
Moderate
Unreviewed
CVE-2025-32275
was published
Apr 10, 2025
Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum allows Identity Spoofing...
Moderate
Unreviewed
CVE-2025-32227
was published
Apr 10, 2025
An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor...
Critical
Unreviewed
CVE-2024-55210
was published
Apr 9, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2025-31170
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58125
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58126
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58127
was published
Apr 7, 2025
Access control vulnerability in the security verification module
Impact: Successful exploitation...
High
Unreviewed
CVE-2024-58124
was published
Apr 7, 2025
A crafted URL containing specific Unicode characters could have hidden the true origin of the...
High
Unreviewed
CVE-2025-3029
was published
Apr 1, 2025
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Moderate
CVE-2025-22223
was published
for
org.springframework.security:spring-security-core
(Maven)
Mar 24, 2025
Fast-JWT Improperly Validates iss Claims
Moderate
CVE-2025-30144
was published
for
fast-jwt
(npm)
Mar 19, 2025
An issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur....
High
Unreviewed
CVE-2025-30142
was published
Mar 18, 2025
On IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's...
Moderate
Unreviewed
CVE-2025-30110
was published
Mar 18, 2025
ProTip!
Advisories are also available from the
GraphQL API