GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,779
Maven
5,000+
npm
4,380
NuGet
770
pip
4,159
Pub
12
RubyGems
963
Rust
1,071
Swift
45
Unreviewed advisories
All unreviewed
5,000+
185 advisories
Filter by severity
Same-origin policy bypass in the Request Handling component. This vulnerability affects Firefox <...
Moderate
Unreviewed
CVE-2025-14331
was published
Dec 9, 2025
Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3...
Moderate
Unreviewed
CVE-2025-8074
was published
Dec 4, 2025
Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin...
Moderate
Unreviewed
CVE-2025-37734
was published
Nov 12, 2025
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80...
Moderate
Unreviewed
CVE-2025-12905
was published
Nov 8, 2025
Liferay Portal fails to verify messages from the cluster network is trusted
Moderate
CVE-2025-62250
was published
for
com.liferay:com.liferay.portal.cluster.multiple
(Maven)
Oct 21, 2025
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an...
Moderate
Unreviewed
CVE-2025-2140
was published
Oct 12, 2025
A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the...
Moderate
Unreviewed
CVE-2025-42706
was published
Oct 8, 2025
A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2025-11304
was published
Oct 5, 2025
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point ...
Moderate
Unreviewed
CVE-2025-20364
was published
Sep 24, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP...
Moderate
Unreviewed
CVE-2025-52621
was published
Aug 16, 2025
In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic...
Moderate
Unreviewed
CVE-2025-53399
was published
Aug 1, 2025
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
Moderate
GHSA-gj52-35xm-gxjh
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
•
withdrawn
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass...
Moderate
Unreviewed
CVE-2025-5824
was published
Jun 26, 2025
The security settings in the SAP Business One Integration Framework are not adequately checked,...
Moderate
Unreviewed
CVE-2025-42998
was published
Jun 10, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Moderate
CVE-2025-30360
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
Error handling for script execution was incorrectly isolated from web content, which could have...
Moderate
Unreviewed
CVE-2025-5263
was published
May 27, 2025
A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2....
Moderate
Unreviewed
CVE-2025-4515
was published
May 10, 2025
@misskey-dev/summaly allows IP Filter Bypass via Redirect
Moderate
GHSA-jqx4-9gpq-rppm
was published
for
@misskey-dev/summaly
(npm)
May 6, 2025
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local...
Moderate
Unreviewed
CVE-2025-43929
was published
Apr 20, 2025
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a...
Moderate
Unreviewed
CVE-2025-3071
was published
Apr 2, 2025
An intent redriction vulnerability exists in the Xiaomi quick App framework application product....
Moderate
Unreviewed
CVE-2024-45353
was published
Mar 27, 2025
A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is...
Moderate
Unreviewed
CVE-2024-45354
was published
Mar 27, 2025
ProTip!
Advisories are also available from the
GraphQL API