GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
41 advisories
Filter by severity
ImageMagick: Policy Bypass in script operation due to missing checks
Low
GHSA-vghg-5jrg-2398
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
ImageMagick: Policy Bypass possible with matrix-backed operations
Low
GHSA-rvhp-75f6-9jqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Low
GHSA-whvh-wf3x-g77j
was published
for
jupyterlab
(pip)
Jul 22, 2026
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers
Low
CVE-2026-55670
was published
for
github.com/zitadel/zitadel
(Go)
Jun 18, 2026
Sulu: Used API Keys may be available via Admin API
Low
GHSA-9m6v-8fxc-4r44
was published
for
sulu/sulu
(Composer)
May 18, 2026
OpenClaw: Paired-device pairing actions were not limited to the caller device
Low
GHSA-xrq9-jm7v-g9h7
was published
for
openclaw
(npm)
Apr 25, 2026
Neo4j Labs MCP Servers: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures
Low
CVE-2026-35402
was published
for
mcp-neo4j-cypher
(pip)
Apr 17, 2026
Weblate: Improper access control for pending tasks in API
Low
CVE-2026-33212
was published
for
weblate
(pip)
Apr 16, 2026
mingSoft MCMS does not properly restrict file uploads
Low
CVE-2026-2666
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 18, 2026
Gitea may send release notification emails for private repositories to users whose access has been revoked
Low
CVE-2026-0798
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Gitea improperly exposes issue titles and repository names through previously started stopwatches
Low
CVE-2026-20883
was published
for
github.com/go-gitea/gitea
(Go)
Jan 23, 2026
Gitea has improper access control for uploaded attachments
Low
CVE-2026-20736
was published
for
code.gitea.io/gitea
(Go)
Jan 23, 2026
Keycloak Admin REST API exposes backend schema and rules
Low
CVE-2025-14083
was published
for
org.keycloak:keycloak-services
(Maven)
Jan 21, 2026
Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
Low
CVE-2026-23522
was published
for
@lobehub/chat
(npm)
Jan 20, 2026
Weblate leaks information via screenshots
Low
CVE-2026-21889
was published
for
weblate
(pip)
Jan 14, 2026
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
Low
CVE-2025-14082
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 10, 2025
open-webui is Vulnerable to Incorrect Access Control
Low
CVE-2025-63681
was published
for
open-webui
(pip)
Dec 4, 2025
Mattermost fails to validate user permissions in Boards
Low
CVE-2025-13870
was published
for
github.com/mattermost/mattermost
(Go)
Dec 2, 2025
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
Vite's `server.fs` settings were not applied to HTML files
Low
CVE-2025-58752
was published
for
vite
(npm)
Sep 9, 2025
Withdrawn Advisory: JHipster allows privilege escalation via a modified authorities parameter
Low
CVE-2025-43712
was published
for
generator-jhipster
(npm)
Jul 25, 2025
•
withdrawn
Magento Improper Access Control vulnerability
Low
CVE-2025-24429
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Umbraco CMS Improper Access Control Vulnerability Allows Low-Privilege Users to Access Webhook API
Low
CVE-2024-48925
was published
for
Umbraco.CMS
(NuGet)
Oct 22, 2024
Magento Open Source Improper Access Control vulnerability
Low
CVE-2024-45149
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Mattermost did not properly restrict channel creation
Low
CVE-2024-39837
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 1, 2024
ProTip!
Advisories are also available from the
GraphQL API