GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
74 advisories
Filter by severity
AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow...
Moderate
Unreviewed
CVE-2025-31971
was published
Aug 28, 2025
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint...
Moderate
Unreviewed
CVE-2025-53073
was published
Jun 26, 2025
Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If...
Moderate
Unreviewed
CVE-2025-41404
was published
Jun 26, 2025
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within...
Moderate
Unreviewed
CVE-2025-52920
was published
Jun 23, 2025
A vulnerability classified as problematic has been found in code-projects Automated Voting System...
Moderate
Unreviewed
CVE-2025-6352
was published
Jun 20, 2025
The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure...
Moderate
Unreviewed
CVE-2022-40845
was published
Nov 15, 2022
In Simple Exam Reviewer Management System v1.0 the User List function has improper access control...
Moderate
Unreviewed
CVE-2022-42197
was published
Oct 20, 2022
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET...
Moderate
Unreviewed
CVE-2022-28365
was published
Apr 10, 2022
Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct...
Moderate
Unreviewed
CVE-2025-46690
was published
Apr 28, 2025
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users...
Moderate
Unreviewed
CVE-2025-27581
was published
Apr 24, 2025
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and...
Moderate
Unreviewed
CVE-2025-2595
was published
Apr 23, 2025
An unauthenticated user can access Identity Manager’s management console specific page URLs....
Moderate
Unreviewed
CVE-2022-25626
was published
Jul 6, 2023
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital...
Moderate
Unreviewed
CVE-2025-2147
was published
Mar 10, 2025
A vulnerability has been identified in SCALANCE XB205-3 (SC, PN) (All versions < V4.5), SCALANCE...
Moderate
Unreviewed
CVE-2023-44320
was published
Nov 14, 2023
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted...
Moderate
Unreviewed
CVE-2021-26085
was published
May 24, 2022
phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images...
Moderate
Unreviewed
CVE-2004-2257
was published
Apr 29, 2022
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct...
Moderate
Unreviewed
CVE-2005-1688
was published
May 1, 2022
When following a redirect to a publicly accessible web extension file, the URL may have been...
Moderate
Unreviewed
CVE-2023-28160
was published
Jun 2, 2023
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests...
Moderate
Unreviewed
CVE-2024-55075
was published
Jan 6, 2025
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is...
Moderate
Unreviewed
CVE-2024-11049
was published
Nov 10, 2024
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7...
Moderate
Unreviewed
CVE-2024-0456
was published
Jan 26, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6...
Moderate
Unreviewed
CVE-2024-0861
was published
Feb 22, 2024
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5,...
Moderate
Unreviewed
CVE-2023-4018
was published
Sep 1, 2023
A CWE-862 “Missing Authorization” vulnerability in the “measure” functionality of the web...
Moderate
Unreviewed
CVE-2023-45598
was published
Mar 5, 2024
A CWE-862 “Missing Authorization” vulnerability in the “file_configuration” functionality of the...
Moderate
Unreviewed
CVE-2023-45596
was published
Mar 5, 2024
ProTip!
Advisories are also available from the
GraphQL API