GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,363 advisories
Filter by severity
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
High
Unreviewed
CVE-2025-61811
was published
Dec 10, 2025
Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to...
High
Unreviewed
CVE-2025-62570
was published
Dec 9, 2025
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-64673
was published
Dec 9, 2025
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker...
High
Unreviewed
CVE-2025-62474
was published
Dec 9, 2025
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-59517
was published
Dec 9, 2025
memos vulnerability allows the creation of arbitrary accounts
High
CVE-2025-65795
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the...
High
Unreviewed
CVE-2025-61229
was published
Dec 1, 2025
A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet...
High
Unreviewed
CVE-2025-63363
was published
Dec 4, 2025
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows...
High
Unreviewed
CVE-2025-57212
was published
Dec 4, 2025
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows...
High
Unreviewed
CVE-2025-57213
was published
Dec 4, 2025
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows...
High
Unreviewed
CVE-2025-57210
was published
Dec 4, 2025
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the...
High
Unreviewed
CVE-2025-56396
was published
Nov 26, 2025
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope...
High
Unreviewed
CVE-2025-46174
was published
Nov 26, 2025
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope...
High
Unreviewed
CVE-2025-46175
was published
Nov 26, 2025
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker...
High
Unreviewed
CVE-2025-59230
was published
Oct 14, 2025
XWiki Jetty Package (XJetty) allows accessing any application file through URL
High
CVE-2025-55749
was published
for
org.xwiki.platform:xwiki-platform-tool-jetty-resources
(Maven)
Dec 1, 2025
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows...
High
Unreviewed
CVE-2025-57489
was published
Dec 1, 2025
Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers...
High
Unreviewed
CVE-2025-55471
was published
Nov 26, 2025
Better Auth Passkey Plugin allows passkey deletion through IDOR
High
GHSA-4vcf-q4xf-f48m
was published
for
@better-auth/passkey
(npm)
Nov 25, 2025
Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions...
High
Unreviewed
CVE-2025-64064
was published
Nov 25, 2025
Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access...
High
Unreviewed
CVE-2025-64066
was published
Nov 25, 2025
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents...
High
Unreviewed
CVE-2016-9905
was published
May 14, 2022
Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier...
High
Unreviewed
CVE-2025-4433
was published
May 30, 2025
Improper access control in secure message component in Devolutions Server allows an authenticated...
High
Unreviewed
CVE-2025-6741
was published
Jul 22, 2025
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert...
High
Unreviewed
CVE-2025-54563
was published
Nov 25, 2025
ProTip!
Advisories are also available from the
GraphQL API