GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,744
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
567 advisories
Filter by severity
Improper Request Caching Lookup in the Auth0 Next.js SDK
Moderate
CVE-2025-67490
was published
for
@auth0/nextjs-auth0
(npm)
Dec 10, 2025
Strimzi allows unrestricted access to all Secrets in the same Kubernetes namespace from Kafka Connect and MirrorMaker 2 operands
High
CVE-2025-66623
was published
for
io.strimzi:strimzi
(Maven)
Dec 5, 2025
Mattermost Server exposes OAuth personal access tokens to attackers
Critical
CVE-2017-18884
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
step-ca Has Improper Authorization Check for SSH Certificate Revocation
Moderate
CVE-2025-66406
was published
for
github.com/smallstep/certificates
(Go)
Dec 3, 2025
Mattermost fails to validate user permissions when deleting comments in Boards
Moderate
CVE-2025-12756
was published
for
github.com/mattermost/mattermost
(Go)
Dec 1, 2025
trytond does not enforce access rights for data export
Moderate
CVE-2025-66424
was published
for
trytond
(pip)
Nov 30, 2025
trytond does not enforce access rights for the route of the HTML editor.
High
CVE-2025-66423
was published
for
trytond
(pip)
Nov 30, 2025
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
Moderate
CVE-2025-66028
was published
for
@oneuptime/common
(npm)
Nov 25, 2025
OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.
High
CVE-2025-65073
was published
for
keystone
(pip)
Nov 17, 2025
Mattermost allows regular users to access archived channel content and files
Low
CVE-2025-41436
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Ignite Realtime Openfire privilege escalation vulnerability
High
CVE-2024-25420
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
Mar 26, 2024
Liferay Portal and DXP do not check permissions of images in a blog entry
Moderate
CVE-2025-62275
was published
for
com.liferay:com.liferay.blogs.item.selector.web
(Maven)
Nov 1, 2025
Mattermost fails to properly restrict access to archived channel search API
Moderate
CVE-2025-11776
was published
for
github.com/mattermost/mattermost
(Go)
Nov 14, 2025
Apollo Federation has Improper Enforcement of Access Control on Transitive Fields
High
GHSA-m8jr-fxqx-8xx6
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Directus has Improper Permission Handling on Deleted Fields
Moderate
CVE-2025-64746
was published
for
directus
(npm)
Nov 14, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-11777
was published
for
github.com/mattermost/mattermost
(Go)
Nov 13, 2025
Incorrect Authorization in Apache Solr
Moderate
CVE-2018-11802
was published
for
org.apache.solr:solr-core
(Maven)
Feb 9, 2022
Magento is affected by an improper authorization vulnerability
Moderate
CVE-2021-36037
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento discloses sensitive information
Moderate
CVE-2021-36039
was published
for
magento/community-edition
(Composer)
May 24, 2022
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Low
CVE-2024-30260
was published
for
undici
(npm)
Apr 4, 2024
ansible-core Incorrect Authorization vulnerability
Moderate
CVE-2024-9902
was published
for
ansible-core
(pip)
Nov 6, 2024
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
High
CVE-2025-59420
was published
for
authlib
(pip)
Sep 22, 2025
Drupal CivicTheme Design System allows Forceful Browsing
High
CVE-2025-12082
was published
for
drupal/civictheme
(Composer)
Oct 30, 2025
Liferay Portal Does Not Limit Access to APIs Before Email Verification
Moderate
CVE-2025-62259
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Moodle sends quiz-related messages to inactive/suspended users
Moderate
CVE-2025-62394
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
ProTip!
Advisories are also available from the
GraphQL API