GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,222
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,157 advisories
Filter by severity
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-53910
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-48731
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-44001
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
Moderate
CVE-2025-55001
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Moderate
CVE-2025-55003
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao TOTP Secrets Engine Code Reuse
Moderate
CVE-2025-55000
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Moderate
CVE-2025-54998
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Ollama allows deletion of arbitrary files
Moderate
CVE-2025-44779
was published
for
github.com/ollama/ollama
(Go)
Aug 7, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA
Moderate
CVE-2025-6013
was published
for
github.com/hashicorp/vault
(Go)
Aug 6, 2025
Grafana Infinity Datasource Plugin SSRF Vulnerability
Moderate
CVE-2025-8341
was published
for
github.com/grafana/grafana-infinity-datasource
(Go)
Aug 4, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass
Moderate
CVE-2025-6004
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability
Moderate
CVE-2025-6015
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Moderate
CVE-2025-6037
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse
Moderate
CVE-2025-6014
was published
for
github.com/hashicorp/vault
(Go)
Aug 1, 2025
OAuth2-Proxy's `--gitlab-group` GitLab Group Authorization config flag stopped working in v7.0.0
Moderate
CVE-2021-21411
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Jul 30, 2025
Moby firewalld reload makes published container ports accessible from remote hosts
Moderate
CVE-2025-54388
was published
for
github.com/docker/docker
(Go)
Jul 29, 2025
Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLs
Moderate
CVE-2025-50738
was published
for
github.com/usememos/memos
(Go)
Jul 29, 2025
Possible ORM Leak Vulnerability in the Harbor
Moderate
CVE-2025-30086
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
Harbor repository description page has Cross-site Scripting vulnerability
Moderate
CVE-2025-32019
was published
for
github.com/goharbor/harbor
(Go)
Jul 23, 2025
Ollama vulnerable to Cross-Domain Token Exposure
Moderate
CVE-2025-51471
was published
for
github.com/ollama/ollama
(Go)
Jul 22, 2025
melange's world-writable permissions expose SBOM files to potential image tampering
Moderate
CVE-2025-54059
was published
for
chainguard.dev/melange
(Go)
Jul 18, 2025
Mattermost Path Traversal vulnerability
Moderate
CVE-2025-6233
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Mattermost Missing Authentication for Critical Function
Moderate
CVE-2025-6226
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Grafana's insecure DingDing Alert integration exposes sensitive information
Moderate
CVE-2025-3415
was published
for
github.com/grafana/grafana
(Go)
Jul 17, 2025
ProTip!
Advisories are also available from the
GraphQL API