GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,877
Erlang
37
GitHub Actions
38
Go
2,532
Maven
5,000+
npm
4,191
NuGet
742
pip
3,970
Pub
12
RubyGems
947
Rust
1,030
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,318 advisories
Filter by severity
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username...
Moderate
Unreviewed
CVE-2025-56764
was published
Sep 29, 2025
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper...
Moderate
Unreviewed
CVE-2025-0663
was published
Sep 23, 2025
A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2025-10772
was published
Sep 22, 2025
Dragonfly's manager makes requests to external endpoints with disabled TLS authentication
Moderate
CVE-2025-59347
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file ...
Moderate
Unreviewed
CVE-2025-10423
was published
Sep 15, 2025
A vulnerability was found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40....
Moderate
Unreviewed
CVE-2025-10288
was published
Sep 12, 2025
Flask App Builder has an Authentication Bypass vulnerability when using non AUTH_DB methods
Moderate
CVE-2025-58065
was published
for
flask-appbuilder
(pip)
Sep 11, 2025
Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One 2.0.2...
Moderate
Unreviewed
CVE-2025-10224
was published
Sep 10, 2025
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0...
Moderate
Unreviewed
CVE-2025-52054
was published
Aug 28, 2025
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown...
Moderate
Unreviewed
CVE-2025-9533
was published
Aug 27, 2025
A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects...
Moderate
Unreviewed
CVE-2025-9100
was published
Aug 18, 2025
A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an...
Moderate
Unreviewed
CVE-2025-8964
was published
Aug 14, 2025
A vulnerability has been found in WinterChenS my-site up to...
Moderate
Unreviewed
CVE-2025-8838
was published
Aug 11, 2025
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This...
Moderate
Unreviewed
CVE-2025-8546
was published
Aug 5, 2025
A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-8348
was published
Jul 31, 2025
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft...
Moderate
Unreviewed
CVE-2025-53771
was published
Jul 21, 2025
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical....
Moderate
Unreviewed
CVE-2025-7897
was published
Jul 20, 2025
A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This...
Moderate
Unreviewed
CVE-2025-7875
was published
Jul 20, 2025
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical....
Moderate
Unreviewed
CVE-2025-7862
was published
Jul 20, 2025
Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of...
Moderate
Unreviewed
CVE-2025-7703
was published
Jul 16, 2025
Directus' insufficient permission checks can enable unauthenticated users to manually trigger Flows
Moderate
CVE-2025-53889
was published
for
directus
(npm)
Jul 15, 2025
An authentication issue was addressed with improved state management. This issue is fixed in App...
Moderate
Unreviewed
CVE-2025-31267
was published
Jul 11, 2025
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to perform...
Moderate
Unreviewed
CVE-2025-49706
was published
Jul 8, 2025
An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version...
Moderate
Unreviewed
CVE-2025-6044
was published
Jul 7, 2025
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97....
Moderate
Unreviewed
CVE-2025-7115
was published
Jul 7, 2025
ProTip!
Advisories are also available from the
GraphQL API