GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,028 advisories
Filter by severity
OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
High
CVE-2025-59048
was published
for
github.com/openbao/openbao-plugins
(Go)
Oct 23, 2025
Ash has authorization bypass when bypass policy condition evaluates to true
High
CVE-2025-48044
was published
for
ash
(Erlang)
Oct 17, 2025
An Incorrect Authorization vulnerability has been identified in Moxa’s network security...
High
Unreviewed
CVE-2025-6892
was published
Oct 17, 2025
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
High
CVE-2025-62506
was published
for
github.com/minio/minio
(Go)
Oct 16, 2025
Magento provides incorrect authorization through a security feature bypass
High
CVE-2025-54263
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Ash Framework: Filter authorization misapplies impossible bypass/runtime policies
High
CVE-2025-48043
was published
for
ash
(Erlang)
Oct 13, 2025
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to...
High
Unreviewed
CVE-2025-11340
was published
Oct 9, 2025
Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to...
High
Unreviewed
CVE-2025-44824
was published
Oct 7, 2025
An access control vulnerability was discovered in the CLI functionality due to a specific access...
High
Unreviewed
CVE-2025-3719
was published
Oct 7, 2025
OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be...
High
Unreviewed
CVE-2025-10696
was published
Oct 3, 2025
VMware Tools for Windows contains an improper authorisation vulnerability due to the way it...
High
Unreviewed
CVE-2025-41246
was published
Sep 29, 2025
Rancher update on users can deny the service to the admin
High
CVE-2024-58260
was published
for
github.com/rancher/rancher
(Go)
Sep 26, 2025
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
High
CVE-2025-59420
was published
for
authlib
(pip)
Sep 22, 2025
The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of...
High
Unreviewed
CVE-2025-10016
was published
Sep 16, 2025
Spring Framework annotation detection mechanism may result in improper authorization
High
CVE-2025-41249
was published
for
org.springframework:spring-core
(Maven)
Sep 16, 2025
Spring Security annotation detection mechanism has authorization bypass
High
CVE-2025-41248
was published
for
org.springframework.security:spring-security-core
(Maven)
Sep 16, 2025
Before action, Ash's hooks may execute in certain scenarios despite a request being forbidden
High
CVE-2025-48042
was published
for
ash
(Erlang)
Sep 15, 2025
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an...
High
Unreviewed
CVE-2025-26436
was published
Sep 5, 2025
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with...
High
Unreviewed
CVE-2025-23256
was published
Sep 5, 2025
In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without...
High
Unreviewed
CVE-2025-48523
was published
Sep 4, 2025
In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due...
High
Unreviewed
CVE-2025-32333
was published
Sep 4, 2025
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to...
High
Unreviewed
CVE-2025-55177
was published
Aug 29, 2025
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their...
High
Unreviewed
CVE-2025-36120
was published
Aug 18, 2025
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web...
High
Unreviewed
CVE-2025-7773
was published
Aug 14, 2025
Magento has incorrect authorization issue that leads to arbitrary file system read
High
CVE-2025-49556
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
ProTip!
Advisories are also available from the
GraphQL API