GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
91 advisories
Filter by severity
Duplicate Advisory: Privilege escalation in sap/cloud-security-client-go
Critical
GHSA-92cg-ghq6-9587
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 12, 2023
•
withdrawn
Duplicate Advisory: Improper JWT Signature Validation in SAP Security Services Library
Critical
GHSA-gcgw-q47m-prvj
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 12, 2023
•
withdrawn
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary...
Critical
Unreviewed
CVE-2024-9862
was published
Oct 17, 2024
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for...
Critical
Unreviewed
CVE-2024-9263
was published
Oct 17, 2024
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man...
Critical
Unreviewed
CVE-2019-19755
was published
Apr 30, 2024
Missing key verification in gost
Critical
CVE-2024-39223
was published
for
github.com/ginuerzh/gost
(Go)
Jul 3, 2024
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without...
Critical
Unreviewed
CVE-2024-31815
was published
Apr 8, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege...
Critical
Unreviewed
CVE-2024-50483
was published
Oct 28, 2024
In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability...
Critical
Unreviewed
CVE-2024-7474
was published
Oct 29, 2024
TeamPass privileges issue
Critical
CVE-2024-50703
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up...
Critical
Unreviewed
CVE-2024-10215
was published
Jan 9, 2025
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
Critical
Unreviewed
CVE-2024-1626
was published
Apr 16, 2024
Insecure direct object reference (IDOR) vulnerability in Anapi Group's h6web, allows an...
Critical
Unreviewed
CVE-2025-1270
was published
Feb 13, 2025
Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper
Critical
CVE-2023-44981
was published
for
org.apache.zookeeper:zookeeper
(Maven)
Oct 11, 2023
The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and...
Critical
Unreviewed
CVE-2024-2472
was published
Jun 14, 2024
SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct...
Critical
Unreviewed
CVE-2024-50685
was published
Feb 26, 2025
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct...
Critical
Unreviewed
CVE-2024-50687
was published
Feb 26, 2025
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct...
Critical
Unreviewed
CVE-2024-50689
was published
Feb 26, 2025
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct...
Critical
Unreviewed
CVE-2024-50686
was published
Feb 26, 2025
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct...
Critical
Unreviewed
CVE-2024-50693
was published
Feb 26, 2025
IDOR Vulnerabilities in ZITADEL's Admin API that Primarily Impact LDAP Configurations
Critical
CVE-2025-27507
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2025
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in...
Critical
Unreviewed
CVE-2024-11284
was published
Mar 14, 2025
The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in...
Critical
Unreviewed
CVE-2024-11285
was published
Mar 14, 2025
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A...
Critical
Unreviewed
CVE-2021-4226
was published
Dec 15, 2022
This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on...
Critical
Unreviewed
CVE-2025-42605
was published
Apr 23, 2025
ProTip!
Advisories are also available from the
GraphQL API