GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12 advisories
Filter by severity
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
Moderate
CVE-2025-55073
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost does not enforce MFA on WebSocket connections
Moderate
CVE-2025-55070
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
Moderate
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
Moderate
CVE-2025-52894
was published
for
github.com/openbao/openbao
(Go)
Jun 26, 2025
Mattermost Missing Authentication for Critical Function
Moderate
CVE-2025-6226
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
Missing Role Based Access Control for the REST handlers in bleve/http package
Moderate
CVE-2022-31022
was published
for
github.com/blevesearch/bleve
(Go)
Jun 3, 2022
Navidrome uses MD5 hashing algorithm
Moderate
CVE-2024-41259
was published
for
github.com/navidrome/navidrome
(Go)
Aug 1, 2024
Unauthenticated Access to sensitive settings in Argo CD
Moderate
CVE-2024-37152
was published
for
github.com/argoproj/argo-cd/v2/server
(Go)
Jun 6, 2024
Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records
Moderate
CVE-2020-15136
was published
for
go.etcd.io/etcd
(Go)
Jan 31, 2024
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Moderate
CVE-2023-41333
was published
for
github.com/cilium/cilium
(Go)
Sep 27, 2023
Denial of service in Grafana
Moderate
CVE-2021-27358
was published
for
github.com/grafana/grafana
(Go)
Feb 15, 2022
ProTip!
Advisories are also available from the
GraphQL API