GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,633
Erlang
34
GitHub Actions
25
Go
2,241
Maven
5,000+
npm
3,902
NuGet
701
pip
3,669
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,717 advisories
Filter by severity
NATS Server may fail to authorize certain Jetstream admin APIs
Critical
CVE-2025-30215
was published
for
github.com/nats-io/nats-server/v2
(Go)
Apr 15, 2025
Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that...
Moderate
Unreviewed
CVE-2025-30733
was published
Apr 15, 2025
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass...
Moderate
Unreviewed
CVE-2024-44843
was published
Apr 15, 2025
In JotUrl 2.0, is possible to bypass security requirements during the password change process.
Moderate
Unreviewed
CVE-2025-24949
was published
Apr 15, 2025
In WhatsUp Gold versions released before 2024.0.3, a
database manipulation
vulnerability...
Moderate
Unreviewed
CVE-2025-2572
was published
Apr 14, 2025
Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header...
Moderate
Unreviewed
CVE-2025-22232
was published
Apr 10, 2025
An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the...
Critical
Unreviewed
CVE-2025-22375
was published
Apr 10, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper...
High
Unreviewed
CVE-2025-30287
was published
Apr 8, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper...
Critical
Unreviewed
CVE-2025-30282
was published
Apr 8, 2025
Joomla CMS Multi-Factor Authentication Bypass
High
CVE-2025-25227
was published
for
joomla/joomla-cms
(Composer)
Apr 8, 2025
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-3268
was published
Apr 4, 2025
Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.
Moderate
Unreviewed
CVE-2025-3062
was published
Apr 1, 2025
Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.
Moderate
Unreviewed
CVE-2025-3061
was published
Apr 1, 2025
This issue was addressed through improved state management. This issue is fixed in visionOS 2.4,...
Critical
Unreviewed
CVE-2025-30430
was published
Apr 1, 2025
A logic issue was addressed with improved state management. This issue is fixed in visionOS 2.4,...
Moderate
Unreviewed
CVE-2025-30432
was published
Apr 1, 2025
Vulnerability in Hewlett Packard Enterprise HPE Insight Cluster Management Utility (CMU).This...
Critical
Unreviewed
CVE-2024-13804
was published
Mar 31, 2025
An attacker with access to the network where the vulnerable device is located could capture...
Moderate
Unreviewed
CVE-2025-2859
was published
Mar 28, 2025
CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability...
Critical
Unreviewed
CVE-2025-2825
was published
Mar 26, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2746
was published
Mar 24, 2025
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the...
Critical
Unreviewed
CVE-2025-2747
was published
Mar 24, 2025
Parse Server has an OAuth login vulnerability
Moderate
CVE-2025-30168
was published
for
parse-server
(npm)
Mar 21, 2025
Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker...
High
Unreviewed
CVE-2024-57490
was published
Mar 21, 2025
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint
High
CVE-2024-8053
was published
for
open-webui
(pip)
Mar 20, 2025
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that...
Moderate
Unreviewed
CVE-2024-12869
was published
Mar 20, 2025
Spring Security Does Not Enforce Password Length
High
CVE-2025-22228
was published
for
org.springframework.security:spring-security-crypto
(Maven)
Mar 20, 2025
ProTip!
Advisories are also available from the
GraphQL API