GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,556
Maven
5,000+
npm
4,228
NuGet
747
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
216 advisories
Filter by severity
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
Moderate
CVE-2025-60868
was published
for
alt-design/alt-redirect
(Composer)
Oct 10, 2025
Python Social Auth - Django has unsafe account association
Moderate
CVE-2025-61783
was published
for
social-auth-app-django
(pip)
Oct 9, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Coder AgentAPI exposed user chat history via a DNS rebinding attack
Moderate
CVE-2025-59956
was published
for
github.com/coder/agentapi
(Go)
Sep 29, 2025
This vulnerability affects Firefox < 143 and Thunderbird < 143.
Moderate
Unreviewed
CVE-2025-10530
was published
Sep 16, 2025
Openfire has potential identity spoofing issue via unsafe CN parsing
Moderate
CVE-2025-59154
was published
for
org.igniterealtime.openfire:xmppserver
(Maven)
Sep 16, 2025
One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to...
Moderate
Unreviewed
CVE-2025-56689
was published
Sep 8, 2025
In multiple locations, there is a possible lock screen bypass due to a logic error in the code....
Moderate
Unreviewed
CVE-2025-26421
was published
Sep 4, 2025
The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest...
Moderate
Unreviewed
CVE-2025-56608
was published
Sep 3, 2025
An Authentication Bypass vulnerability in Blue Access' Cobalt X1 thru 02.000.187 allows an...
Moderate
Unreviewed
CVE-2025-50454
was published
Aug 5, 2025
CSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to...
Moderate
Unreviewed
CVE-2025-46018
was published
Aug 1, 2025
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd...
Moderate
Unreviewed
CVE-2025-34065
was published
Jul 1, 2025
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd...
Moderate
Unreviewed
CVE-2025-34053
was published
Jul 1, 2025
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using...
Moderate
Unreviewed
CVE-2025-23168
was published
Jun 19, 2025
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
Moderate
CVE-2025-48937
was published
for
matrix-sdk-crypto
(Rust)
Jun 10, 2025
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a...
Moderate
Unreviewed
CVE-2025-5067
was published
May 27, 2025
The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary...
Moderate
Unreviewed
CVE-2025-48027
was published
May 15, 2025
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to...
Moderate
Unreviewed
CVE-2025-3909
was published
May 14, 2025
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by...
Moderate
Unreviewed
CVE-2025-27695
was published
May 8, 2025
An app could impersonate system notifications. Sensitive notifications now require restricted...
Moderate
Unreviewed
CVE-2025-24091
was published
Apr 30, 2025
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Moderate
CVE-2025-32788
was published
for
octoprint
(pip)
Apr 22, 2025
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system...
Moderate
Unreviewed
CVE-2023-5616
was published
Apr 15, 2025
Authentication Bypass by Spoofing vulnerability in Asgaros Asgaros Forum allows Identity Spoofing...
Moderate
Unreviewed
CVE-2025-32227
was published
Apr 10, 2025
Authentication Bypass by Spoofing vulnerability in Ays Pro Survey Maker allows Identity Spoofing....
Moderate
Unreviewed
CVE-2025-32275
was published
Apr 10, 2025
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Moderate
CVE-2025-22223
was published
for
org.springframework.security:spring-security-core
(Maven)
Mar 24, 2025
ProTip!
Advisories are also available from the
GraphQL API