GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
275 advisories
Filter by severity
Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Moderate
CVE-2025-48935
was published
for
deno
(Rust)
Jun 4, 2025
Deno run with --allow-read and --deny-read flags results in allowed
Moderate
CVE-2025-48888
was published
for
deno
(Rust)
Jun 4, 2025
WSO2 products vulnerable to privilege escalation due to business logic flaw in SOAP admin services
Moderate
CVE-2024-7096
was published
for
org.wso2.am:am-parent
(Maven)
May 30, 2025
Mattermost improperly allows team administrators to modify team invites
Moderate
CVE-2025-3913
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 29, 2025
Mattermost Fails to Verify User's Permissions When Accessing Groups
Moderate
CVE-2025-2527
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 15, 2025
Mattermost Fails to Validate Team Invite Permissions
Moderate
CVE-2025-3446
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 15, 2025
Apache Superset Allows Ownership Takeover
Moderate
CVE-2025-27696
was published
for
apache-superset
(pip)
May 13, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization
Moderate
CVE-2025-3879
was published
for
github.com/hashicorp/vault
(Go)
May 2, 2025
OpenFGA Authorization Bypass
Moderate
CVE-2025-46331
was published
for
github.com/openfga/openfga
(Go)
Apr 30, 2025
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-2564
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Mattermost Incorrect Authorization vulnerability
Moderate
CVE-2025-27571
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 16, 2025
Mattermost Fails to Restrict Certain Operations on System Admins
Moderate
CVE-2025-32093
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 14, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
Mattermost Fails to Enforce Certain Search APIs
Moderate
CVE-2025-30179
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost allows members with permission to convert public channels to private and convert private to public
Moderate
CVE-2025-27933
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
Moderate
CVE-2025-24920
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Restrict Command Execution in Archived Channels
Moderate
CVE-2025-25274
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 21, 2025
Mattermost Fails to Properly Perform Viewer Role Authorization
Moderate
CVE-2025-1472
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 19, 2025
Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Moderate
CVE-2025-27602
was published
for
Umbraco.Cms.Web.Backoffice
(NuGet)
Mar 11, 2025
Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
Moderate
CVE-2025-27601
was published
for
Umbraco.Cms.Api.Management
(NuGet)
Mar 11, 2025
ProTip!
Advisories are also available from the
GraphQL API