GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            968 advisories
        Filter by severity
        
      
      
    
                    
                      An improper access control vulnerability was identified in GitHub Enterprise Server that allowed...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8447
                      
                      was published
                      Aug 26, 2025 
                    
                  
                    
                      An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45968
                      
                      was published
                      Aug 25, 2025 
                    
                  
                    
                      An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55621
                      
                      was published
                      Aug 22, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57886
                      
                      was published
                      Aug 22, 2025 
                    
                  
                    
                      Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-55370
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9263
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9264
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5261
                      
                      was published
                      Aug 20, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in paymayapg Maya Business allows...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53208
                      
                      was published
                      Aug 20, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to Insecure Direct Object Reference
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43732
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.roles.selector.web
                        
                        (Maven)
                      Aug 18, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors allows...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54691
                      
                      was published
                      Aug 14, 2025 
                    
                  
                    
                      An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-8770
                      
                      was published
                      Aug 13, 2025 
                    
                  
                    
                      ServiceNow has addressed a Broken Access Control vulnerability that was identified in the...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3089
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in ABB Aspect.This issue affects...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-53189
                      
                      was published
                      Aug 11, 2025 
                    
                  
                    
                      The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-4796
                      
                      was published
                      Aug 8, 2025 
                    
                  
                    
                      IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF005 and 24.0.1 through 24.0.1 IF002...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-36023
                      
                      was published
                      Aug 8, 2025 
                    
                  
                    
                      An Insecure Direct Object Reference (IDOR) in Sage DPW v2024_12_004 and below allows unauthorized...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-51533
                      
                      was published
                      Aug 7, 2025 
                    
                  
                    
                      CWE-639 Authorization Bypass Through User-Controlled Key
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46386
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      CWE-639 Authorization Bypass Through User-Controlled Key
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-46387
                      
                      was published
                      Aug 6, 2025 
                    
                  
                    
                      Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-51628
                      
                      was published
                      Aug 5, 2025 
                    
                  
                    
                      An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50340
                      
                      was published
                      Aug 4, 2025 
                    
                  
                    
                      The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-5947
                      
                      was published
                      Aug 1, 2025 
                    
                  
                    
                      CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-50849
                      
                      was published
                      Jul 31, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52448
                      
                      was published
                      Jul 25, 2025 
                    
                  
                    
                      Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-52447
                      
                      was published
                      Jul 25, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API