GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,750 advisories
Filter by severity
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
Moderate
Unreviewed
CVE-2025-64897
was published
Dec 10, 2025
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2,...
Moderate
Unreviewed
CVE-2025-59810
was published
Dec 9, 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected...
Moderate
Unreviewed
CVE-2025-40939
was published
Dec 9, 2025
memos vulnerability allows arbitrarily modification or deletion registered identity providers
Moderate
CVE-2025-65797
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily modification or deletion of attachments
Moderate
CVE-2025-65798
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily reactions deletion
Moderate
CVE-2025-65796
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted...
Moderate
Unreviewed
CVE-2025-14219
was published
Dec 8, 2025
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file...
Moderate
Unreviewed
CVE-2025-14199
was published
Dec 7, 2025
A security flaw has been discovered in code-projects Employee Profile Management System 1.0....
Moderate
Unreviewed
CVE-2025-14195
was published
Dec 7, 2025
Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~...
Moderate
Unreviewed
CVE-2025-65841
was published
Dec 3, 2025
A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function...
Moderate
Unreviewed
CVE-2025-13949
was published
Dec 3, 2025
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
Moderate
CVE-2025-66454
was published
for
arcade-mcp-server
(pip)
Dec 2, 2025
Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic
Moderate
CVE-2025-64715
was published
for
Ciliumgithub.com/cilium/cilium
(Go)
Dec 1, 2025
A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an...
Moderate
Unreviewed
CVE-2025-13815
was published
Dec 1, 2025
Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway...
Moderate
Unreviewed
CVE-2025-65238
was published
Nov 26, 2025
Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC...
Moderate
Unreviewed
CVE-2025-65239
was published
Nov 26, 2025
OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation
Moderate
CVE-2025-66028
was published
for
@oneuptime/common
(npm)
Nov 25, 2025
A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This...
Moderate
Unreviewed
CVE-2025-13573
was published
Nov 24, 2025
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the...
Moderate
Unreviewed
CVE-2025-13574
was published
Nov 24, 2025
A weakness has been identified in ashraf-kabir travel-agency up to...
Moderate
Unreviewed
CVE-2025-13544
was published
Nov 23, 2025
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-64660
was published
Nov 21, 2025
phppgadmin contains an incorrect access control vulnerability
Moderate
CVE-2025-60799
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element...
Moderate
Unreviewed
CVE-2025-13423
was published
Nov 20, 2025
A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-13411
was published
Nov 19, 2025
An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6...
Moderate
Unreviewed
CVE-2025-63214
was published
Nov 19, 2025
ProTip!
Advisories are also available from the
GraphQL API