Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,717 advisories

Loading
NATS Server may fail to authorize certain Jetstream admin APIs Critical
CVE-2025-30215 was published for github.com/nats-io/nats-server/v2 (Go) Apr 15, 2025
zarqman
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass... Moderate Unreviewed
CVE-2024-44843 was published Apr 15, 2025
An authentication bypass vulnerability was found in Videx's CyberAudit-Web. Through the... Critical Unreviewed
CVE-2025-22375 was published Apr 10, 2025
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper... Critical Unreviewed
CVE-2025-30282 was published Apr 8, 2025
Joomla CMS Multi-Factor Authentication Bypass High
CVE-2025-25227 was published for joomla/joomla-cms (Composer) Apr 8, 2025
Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*. Moderate Unreviewed
CVE-2025-3061 was published Apr 1, 2025
Parse Server has an OAuth login vulnerability Moderate
CVE-2025-30168 was published for parse-server (npm) Mar 21, 2025
tiaod dblythy
mtrezza
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint High
CVE-2024-8053 was published for open-webui (pip) Mar 20, 2025
Spring Security Does Not Enforce Password Length High
CVE-2025-22228 was published for org.springframework.security:spring-security-crypto (Maven) Mar 20, 2025
ProTip! Advisories are also available from the GraphQL API