GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,646 advisories
Filter by severity
A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet...
High
Unreviewed
CVE-2025-63363
was published
Dec 4, 2025
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows...
High
Unreviewed
CVE-2025-57210
was published
Dec 4, 2025
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows...
High
Unreviewed
CVE-2025-57212
was published
Dec 4, 2025
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows...
High
Unreviewed
CVE-2025-57213
was published
Dec 4, 2025
open-webui is Vulnerable to Incorrect Access Control
Low
CVE-2025-63681
was published
for
open-webui
(pip)
Dec 4, 2025
Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~...
Moderate
Unreviewed
CVE-2025-65841
was published
Dec 3, 2025
A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function...
Moderate
Unreviewed
CVE-2025-13949
was published
Dec 3, 2025
Mautic user without privileged access to the Marketplace can install and uninstall composer packages
Critical
CVE-2025-13828
was published
for
mautic/core
(Composer)
Dec 2, 2025
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a...
Critical
Unreviewed
CVE-2025-59703
was published
Dec 2, 2025
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
Moderate
CVE-2025-66454
was published
for
arcade-mcp-server
(pip)
Dec 2, 2025
Mattermost fails to validate user permissions in Boards
Low
CVE-2025-13870
was published
for
github.com/mattermost/mattermost
(Go)
Dec 2, 2025
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Moderate
CVE-2025-64715
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Dec 1, 2025
XWiki Jetty Package (XJetty) allows accessing any application file through URL
High
CVE-2025-55749
was published
for
org.xwiki.platform:xwiki-platform-tool-jetty-resources
(Maven)
Dec 1, 2025
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows...
High
Unreviewed
CVE-2025-57489
was published
Dec 1, 2025
A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an...
Moderate
Unreviewed
CVE-2025-13815
was published
Dec 1, 2025
An unauthenticated administrative access vulnerability exists in the open-source HashTech project...
Critical
Unreviewed
CVE-2025-65276
was published
Nov 26, 2025
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC...
Moderate
Unreviewed
CVE-2025-65239
was published
Nov 26, 2025
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope...
High
Unreviewed
CVE-2025-46174
was published
Nov 26, 2025
Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway...
Moderate
Unreviewed
CVE-2025-65238
was published
Nov 26, 2025
Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers...
High
Unreviewed
CVE-2025-55471
was published
Nov 26, 2025
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and...
Critical
Unreviewed
CVE-2025-55469
was published
Nov 26, 2025
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope...
High
Unreviewed
CVE-2025-46175
was published
Nov 26, 2025
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the...
High
Unreviewed
CVE-2025-56396
was published
Nov 26, 2025
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
Moderate
CVE-2025-66028
was published
for
@oneuptime/common
(npm)
Nov 25, 2025
Better Auth Passkey Plugin allows passkey deletion through IDOR
High
GHSA-4vcf-q4xf-f48m
was published
for
@better-auth/passkey
(npm)
Nov 25, 2025
ProTip!
Advisories are also available from the
GraphQL API