GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
43
Go
3,181
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,474
Pub
12
RubyGems
991
Rust
1,185
Swift
51
Unreviewed advisories
All unreviewed
5,000+
154 advisories
Filter by severity
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access...
Low
Unreviewed
CVE-2026-24509
was published
Mar 11, 2026
mingSoft MCMS does not properly restrict file uploads
Low
CVE-2026-2666
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 18, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
Low
Unreviewed
CVE-2026-20601
was published
Feb 12, 2026
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A...
Low
Unreviewed
CVE-2026-20642
was published
Feb 12, 2026
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program...
Low
Unreviewed
CVE-2025-6592
was published
Feb 3, 2026
Gitea may send release notification emails for private repositories to users whose access has been revoked
Low
CVE-2026-0798
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
CVE-2026-20883
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea has improper access control for uploaded attachments
Low
CVE-2026-20736
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Keycloak Admin REST API exposes backend schema and rules
Low
CVE-2025-14083
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
Low
CVE-2026-23522
was published
for
@lobehub/chat
(npm)
Jan 20, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3...
Low
Unreviewed
CVE-2025-31186
was published
Jan 16, 2026
This issue was addressed with improved permissions checking. This issue is fixed in macOS Sequoia...
Low
Unreviewed
CVE-2024-44210
was published
Jan 16, 2026
This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and...
Low
Unreviewed
CVE-2024-54556
was published
Jan 16, 2026
Weblate leaks information via screenshots
Low
CVE-2026-21889
was published
for
weblate
(pip)
Jan 14, 2026
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.3,...
Low
Unreviewed
CVE-2025-43518
was published
Dec 12, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
Low
Unreviewed
CVE-2025-43404
was published
Dec 12, 2025
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
Low
CVE-2025-14082
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 10, 2025
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.4,...
Low
Unreviewed
CVE-2025-59923
was published
Dec 9, 2025
open-webui is Vulnerable to Incorrect Access Control
Low
CVE-2025-63681
was published
for
open-webui
(pip)
Dec 4, 2025
Mattermost fails to validate user permissions in Boards
Low
CVE-2025-13870
was published
for
github.com/mattermost/mattermost
(Go)
Dec 2, 2025
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and...
Low
Unreviewed
CVE-2025-31216
was published
Nov 22, 2025
Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User...
Low
Unreviewed
CVE-2025-32037
was published
Nov 11, 2025
Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within...
Low
Unreviewed
CVE-2025-24314
was published
Nov 11, 2025
This issue was addressed by restricting options offered on a locked device. This issue is fixed...
Low
Unreviewed
CVE-2025-43408
was published
Nov 4, 2025
A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An...
Low
Unreviewed
CVE-2025-43309
was published
Nov 4, 2025
ProTip!
Advisories are also available from the
GraphQL API