GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
566 advisories
Filter by severity
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
step-ca Has Improper Authorization Check for SSH Certificate Revocation
Moderate
CVE-2025-66406
was published
for
github.com/smallstep/certificates
(Go)
Dec 3, 2025
Mattermost fails to validate user permissions when deleting comments in Boards
Moderate
CVE-2025-12756
was published
for
github.com/mattermost/mattermost
(Go)
Dec 1, 2025
trytond does not enforce access rights for the route of the HTML editor.
High
CVE-2025-66423
was published
for
trytond
(pip)
Nov 30, 2025
trytond does not enforce access rights for data export
Moderate
CVE-2025-66424
was published
for
trytond
(pip)
Nov 30, 2025
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
Moderate
CVE-2025-66028
was published
for
@oneuptime/common
(npm)
Nov 25, 2025
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
High
CVE-2025-65073
was published
for
keystone
(pip)
Nov 17, 2025
Apollo Federation has Improper Enforcement of Access Control on Transitive Fields
High
GHSA-m8jr-fxqx-8xx6
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Directus has Improper Permission Handling on Deleted Fields
Moderate
CVE-2025-64746
was published
for
directus
(npm)
Nov 14, 2025
Mattermost allows regular users to access archived channel content and files
Low
CVE-2025-41436
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost fails to properly restrict access to archived channel search API
Moderate
CVE-2025-11776
was published
for
github.com/mattermost/mattermost
(Go)
Nov 14, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-11777
was published
for
github.com/mattermost/mattermost
(Go)
Nov 13, 2025
Liferay Portal and DXP do not check permissions of images in a blog entry
Moderate
CVE-2025-62275
was published
for
com.liferay:com.liferay.blogs.item.selector.web
(Maven)
Nov 1, 2025
Drupal CivicTheme Design System allows Forceful Browsing
High
CVE-2025-12082
was published
for
drupal/civictheme
(Composer)
Oct 30, 2025
Liferay Portal Does Not Limit Access to APIs Before Email Verification
Moderate
CVE-2025-62259
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
High
CVE-2025-59048
was published
for
github.com/openbao/openbao-plugins
(Go)
Oct 23, 2025
Moodle sends quiz-related messages to inactive/suspended users
Moderate
CVE-2025-62394
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
Moderate
GHSA-m895-2hj3-8cg9
was published
for
shopware/core
(Composer)
Oct 21, 2025
Ash has authorization bypass when bypass policy condition evaluates to true
High
CVE-2025-48044
was published
for
ash
(Erlang)
Oct 17, 2025
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
High
CVE-2025-62506
was published
for
github.com/minio/minio
(Go)
Oct 16, 2025
Mattermost has an Incorrect Authorization vulnerability
Low
CVE-2025-10545
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Magento allows incorrect authorization
Moderate
CVE-2025-54265
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento provides incorrect authorization through a security feature bypass
High
CVE-2025-54263
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento vulnerable to privilege escalation due to incorrect authorization
Moderate
CVE-2025-54267
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Liferay Publications is vulnerable to Incorrect Authorization
Moderate
CVE-2025-62243
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 13, 2025
ProTip!
Advisories are also available from the
GraphQL API