GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
281 advisories
Filter by severity
Karmada Dashboard API Unauthorized Access Vulnerability
Critical
CVE-2025-62714
was published
for
github.com/karmada-io/dashboard
(Go)
Oct 24, 2025
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is...
Critical
Unreviewed
CVE-2022-0543
was published
Feb 19, 2022
lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST ...
Critical
Unreviewed
CVE-2024-8999
was published
Mar 20, 2025
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control,...
Critical
Unreviewed
CVE-2024-9095
was published
Mar 20, 2025
An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to...
Critical
Unreviewed
CVE-2024-7475
was published
Oct 29, 2024
Melis Platform CMS Unauthenticated Admin Account Creation
Critical
CVE-2025-10352
was published
for
melisplatform/melis-core
(Composer)
Oct 8, 2025
The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2020-36852
was published
Oct 1, 2025
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11...
Critical
Unreviewed
CVE-2025-54943
was published
Sep 25, 2025
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is...
Critical
Unreviewed
CVE-2025-9054
was published
Sep 24, 2025
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized...
Critical
Unreviewed
CVE-2025-10690
was published
Sep 19, 2025
Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
Critical
CVE-2024-38002
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Missing Authorization vulnerability in Hamid Alinia Login with phone number.This issue affects...
Critical
Unreviewed
CVE-2024-32832
was published
Aug 31, 2025
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user...
Critical
Unreviewed
CVE-2025-52352
was published
Aug 21, 2025
The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2025-8898
was published
Aug 16, 2025
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform...
Critical
Unreviewed
CVE-2025-50171
was published
Aug 12, 2025
The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing...
Critical
Unreviewed
CVE-2025-8059
was published
Aug 12, 2025
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Privilege Escalation due to missing...
Critical
Unreviewed
CVE-2025-6380
was published
Jul 25, 2025
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings |...
Critical
Unreviewed
CVE-2025-6441
was published
Jul 25, 2025
The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead...
Critical
Unreviewed
CVE-2015-10143
was published
Jul 25, 2025
The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing...
Critical
Unreviewed
CVE-2025-6187
was published
Jul 22, 2025
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2025-49747
was published
Jul 18, 2025
The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-5394
was published
Jul 15, 2025
Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension...
Critical
Unreviewed
CVE-2025-53495
was published
Jul 7, 2025
: Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension...
Critical
Unreviewed
CVE-2025-53499
was published
Jul 7, 2025
The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to...
Critical
Unreviewed
CVE-2025-5304
was published
Jun 28, 2025
ProTip!
Advisories are also available from the
GraphQL API