GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
Missing Authorization in TeamPass
High
CVE-2020-11671
was published
for
nilsteampassnet/teampass
(Composer)
Jul 26, 2021
Missing Authorization in DayByDay CRM
High
CVE-2022-22111
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
Improper Privilege Management in Snipe-IT
High
CVE-2022-0611
was published
for
snipe/snipe-it
(Composer)
Feb 17, 2022
Dolibarr arbitrary commands execution
High
CVE-2018-10092
was published
for
dolibarr/dolibarr
(Composer)
May 13, 2022
Moodle incorrect access control
High
CVE-2020-25629
was published
for
moodle/moodle
(Composer)
May 24, 2022
Snipe-IT allows users to promote or demote themselves or other users
High
CVE-2024-5685
was published
for
snipe/snipe-it
(Composer)
Jun 14, 2024
Mautic vulnerable to Improper Access Control in UI upgrade process
High
CVE-2022-25768
was published
for
mautic/core
(Composer)
Sep 18, 2024
Drupal Authenticator Login Missing Authorization vulnerability
High
CVE-2025-31681
was published
for
drupal/alogin
(Composer)
Apr 1, 2025
Drupal Open Social Missing Authorization vulnerability
High
CVE-2025-31686
was published
for
goalgorilla/open_social
(Composer)
Apr 1, 2025
Drupal OAuth2 Server Missing Authorization vulnerability
High
CVE-2025-31691
was published
for
drupal/oauth2_server
(Composer)
Apr 1, 2025
HAX CMS API Lacks Authorization Checks
High
CVE-2025-54378
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 25, 2025
UnoPim has Broken Access Control
High
CVE-2025-55741
was published
for
unopim/unopim
(Composer)
Aug 22, 2025
Drupal Acquia DAM allows Forceful Browsing
High
CVE-2025-9954
was published
for
drupal/acquia_dam
(Composer)
Oct 30, 2025
TYPO3 CMS Allows Broken Access Control in Recycler Module
High
CVE-2025-59022
was published
for
typo3/cms-recycler
(Composer)
Jan 13, 2026
phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint
High
CVE-2026-27836
was published
for
thorsten/phpmyfaq
(Composer)
Feb 27, 2026
Craft CMS has IDOR via GraphQL @parseRefs
High
CVE-2026-28696
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability
High
CVE-2026-32268
was published
for
craftcms/azure-blob
(Composer)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API