GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,655
Maven
5,000+
npm
4,284
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
75 advisories
Filter by severity
Magento is affected by an improper authorization vulnerability
Moderate
CVE-2021-36037
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento discloses sensitive information
Moderate
CVE-2021-36039
was published
for
magento/community-edition
(Composer)
May 24, 2022
Moodle sends quiz-related messages to inactive/suspended users
Moderate
CVE-2025-62394
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Magento Security feature bypass
Moderate
CVE-2025-49550
was published
for
magento/community-edition
(Composer)
Jun 26, 2025
Magento vulnerable to privilege escalation due to incorrect authorization
Moderate
CVE-2025-54267
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
Moderate
GHSA-m895-2hj3-8cg9
was published
for
shopware/core
(Composer)
Oct 21, 2025
Magento allows incorrect authorization
Moderate
CVE-2025-54265
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
MantisBT Incorrect Authorization in bug_actiongroup_page.php
Moderate
CVE-2020-29605
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
MantisBT unauthorized users able to access private files
Moderate
CVE-2020-25781
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24436
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24437
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Moodle does not properly restrict comment capabilities
Moderate
CVE-2011-4297
was published
for
moodle/moodle
(Composer)
May 13, 2022
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-38218
was published
for
magento/community-edition
(Composer)
Oct 13, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-38209
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source affected by Improper Input Validation
Moderate
CVE-2023-22248
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-29288
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-22251
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Incorrect Authorization vulnerability
Moderate
CVE-2025-24421
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API