GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,080
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
190 advisories
Filter by severity
The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary...
High
Unreviewed
CVE-2025-64065
was published
Nov 25, 2025
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but...
High
Unreviewed
CVE-2025-64062
was published
Nov 25, 2025
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized...
High
Unreviewed
CVE-2025-64655
was published
Nov 21, 2025
The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-11521
was published
Nov 11, 2025
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is...
High
Unreviewed
CVE-2025-4519
was published
Nov 7, 2025
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in...
High
Unreviewed
CVE-2024-40814
was published
Jul 30, 2024
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight...
High
Unreviewed
CVE-2023-47166
was published
May 1, 2024
The issue was addressed with improved restriction of data container access. This issue is fixed...
High
Unreviewed
CVE-2024-40783
was published
Jul 30, 2024
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5. An...
High
Unreviewed
CVE-2025-31249
was published
May 13, 2025
A race condition flaw was found in sssd where the GPO policy is not consistently applied for...
High
Unreviewed
CVE-2023-3758
was published
Apr 18, 2024
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5...
High
Unreviewed
CVE-2018-13382
was published
May 24, 2022
A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute...
High
Unreviewed
CVE-2024-8764
was published
Mar 20, 2025
In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create...
High
Unreviewed
CVE-2024-9000
was published
Mar 20, 2025
In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to...
High
Unreviewed
CVE-2024-9096
was published
Mar 20, 2025
A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover...
High
Unreviewed
CVE-2024-12880
was published
Mar 20, 2025
The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main'...
High
Unreviewed
CVE-2024-4254
was published
Jun 4, 2024
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization...
High
Unreviewed
CVE-2024-7015
was published
Sep 9, 2024
Redis Enterprise Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-59271
was published
Oct 9, 2025
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317...
High
Unreviewed
CVE-2025-59305
was published
Sep 24, 2025
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due...
High
Unreviewed
CVE-2025-26430
was published
Sep 5, 2025
The Application is vulnerable to an Unauthenticated Arbitrary File Read. This affects the
Agent...
High
Unreviewed
CVE-2024-26291
was published
Jul 14, 2025
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute...
High
Unreviewed
CVE-2025-49701
was published
Jul 8, 2025
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without...
High
Unreviewed
CVE-2025-6713
was published
Jul 7, 2025
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization...
High
Unreviewed
CVE-2025-46840
was published
Jun 11, 2025
Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a...
High
Unreviewed
CVE-2024-43706
was published
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API