GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,778
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,966
NuGet
713
pip
3,759
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
277 advisories
Filter by severity
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme,...
Critical
Unreviewed
CVE-2025-4973
was published
Jun 12, 2025
CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through...
Critical
Unreviewed
CVE-2025-30184
was published
Jun 10, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password...
High
Unreviewed
CVE-2025-31019
was published
Jun 9, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India...
Critical
Unreviewed
CVE-2025-31022
was published
Jun 9, 2025
Vulnerability that cards can call unauthorized APIs in the FRS process
Impact: Successful...
Moderate
Unreviewed
CVE-2025-48904
was published
Jun 6, 2025
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2025-4797
was published
Jun 3, 2025
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
High
Unreviewed
CVE-2025-5190
was published
May 30, 2025
In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre...
High
Unreviewed
CVE-2025-4687
was published
May 29, 2025
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover...
Moderate
Unreviewed
CVE-2025-48926
was published
May 28, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts...
High
Unreviewed
CVE-2025-47461
was published
May 23, 2025
Affected Vertiv products do not properly protect webserver functions that could allow an attacker...
Critical
Unreviewed
CVE-2025-46412
was published
May 21, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48010
was published
May 21, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time...
Moderate
Unreviewed
CVE-2025-48011
was published
May 21, 2025
The TYPO3 CMS Backend has Broken Authentication in Backend MFA
High
CVE-2025-47941
was published
for
typo3/cms-backend
(Composer)
May 20, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Masteriyo Masteriyo -...
Moderate
Unreviewed
CVE-2024-33939
was published
May 19, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA -...
High
Unreviewed
CVE-2025-47710
was published
May 14, 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA -...
High
Unreviewed
CVE-2025-47707
was published
May 14, 2025
It was possible to craft an email that showed a tracking link as an attachment. If the user...
High
Unreviewed
CVE-2025-3932
was published
May 14, 2025
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and...
Moderate
Unreviewed
CVE-2025-4427
was published
May 13, 2025
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024...
Critical
Unreviewed
CVE-2025-22462
was published
May 13, 2025
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with...
High
Unreviewed
CVE-2025-40581
was published
May 13, 2025
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to...
Moderate
Unreviewed
CVE-2025-0549
was published
May 9, 2025
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication...
Critical
Unreviewed
CVE-2025-3844
was published
May 7, 2025
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus...
Critical
Unreviewed
CVE-2024-12225
was published
May 6, 2025
The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-1909
was published
May 5, 2025
ProTip!
Advisories are also available from the
GraphQL API