GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,222
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
152 advisories
Filter by severity
A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/...
Moderate
Unreviewed
CVE-2025-11280
was published
Oct 5, 2025
Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api...
Moderate
Unreviewed
CVE-2025-59797
was published
Sep 22, 2025
A vulnerability has been found in roncoo roncoo-pay up to...
Low
Unreviewed
CVE-2025-10287
was published
Sep 12, 2025
AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability. The issue may allow...
Moderate
Unreviewed
CVE-2025-31971
was published
Aug 28, 2025
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint...
Moderate
Unreviewed
CVE-2025-53073
was published
Jun 26, 2025
Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If...
Moderate
Unreviewed
CVE-2025-41404
was published
Jun 26, 2025
Innoshop through 0.4.1 allows Insecure Direct Object Reference (IDOR) at multiple places within...
Moderate
Unreviewed
CVE-2025-52920
was published
Jun 23, 2025
A vulnerability classified as problematic has been found in code-projects Automated Voting System...
Moderate
Unreviewed
CVE-2025-6352
was published
Jun 20, 2025
The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource Location
High
CVE-2025-48201
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object Reference
High
CVE-2025-48205
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
reint_downloadmanager TYPO3 Extension is susceptible to Insecure Direct Object Reference
Moderate
CVE-2025-48207
was published
for
renolit/reint-downloadmanager
(Composer)
May 21, 2025
The femanager TYPO3 extension allows Insecure Direct Object Reference
Moderate
CVE-2025-48202
was published
for
in2code/femanager
(Composer)
May 21, 2025
Grokability Snipe-IT has incorrect authorization for accessing asset information
Moderate
CVE-2025-47226
was published
for
snipe/snipe-it
(Composer)
May 2, 2025
Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct...
Moderate
Unreviewed
CVE-2025-46690
was published
Apr 28, 2025
NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users...
Moderate
Unreviewed
CVE-2025-27581
was published
Apr 24, 2025
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and...
Moderate
Unreviewed
CVE-2025-2595
was published
Apr 23, 2025
The Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via ...
High
Unreviewed
CVE-2025-32367
was published
Apr 11, 2025
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all...
Critical
Unreviewed
CVE-2025-26689
was published
Mar 31, 2025
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an...
Critical
Unreviewed
CVE-2025-1542
was published
Mar 26, 2025
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital...
Moderate
Unreviewed
CVE-2025-2147
was published
Mar 10, 2025
Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests...
Moderate
Unreviewed
CVE-2024-55075
was published
Jan 6, 2025
A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is...
Moderate
Unreviewed
CVE-2024-11049
was published
Nov 10, 2024
Direct Request ('Forced Browsing') vulnerability in Apache OFBiz.
This issue affects Apache...
High
Unreviewed
CVE-2024-45195
was published
Sep 4, 2024
A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been...
Moderate
Unreviewed
CVE-2024-7753
was published
Aug 14, 2024
An improper authentication vulnerability affecting Vonets
industrial wifi bridge relays...
Moderate
Unreviewed
CVE-2024-42001
was published
Aug 12, 2024
ProTip!
Advisories are also available from the
GraphQL API