GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,736
Maven
5,000+
npm
4,336
NuGet
764
pip
4,110
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
433 advisories
Filter by severity
1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers
Moderate
CVE-2025-66508
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
1Panel – CAPTCHA Bypass via Client-Controlled Flag
High
CVE-2025-66507
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 8, 2025
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the...
High
Unreviewed
CVE-2025-54305
was published
Dec 4, 2025
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets....
Moderate
Unreviewed
CVE-2025-66270
was published
Dec 5, 2025
A flaw exists in the verification of application installation sources within ColorOS. Under...
Moderate
Unreviewed
CVE-2025-27389
was published
Dec 5, 2025
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a...
Moderate
Unreviewed
CVE-2025-59699
was published
Dec 2, 2025
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41...
Moderate
Unreviewed
CVE-2025-13634
was published
Dec 2, 2025
Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a...
Moderate
Unreviewed
CVE-2025-13636
was published
Dec 2, 2025
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local...
Moderate
Unreviewed
CVE-2025-13635
was published
Dec 2, 2025
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication...
Critical
Unreviewed
CVE-2023-30803
was published
Oct 10, 2023
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18...
Moderate
Unreviewed
CVE-2025-12653
was published
Nov 26, 2025
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Moderate
CVE-2025-63700
was published
for
@clerk/clerk-js
(npm)
Nov 20, 2025
An attacker could take over a Looker account in a Looker instance configured with OIDC...
Critical
Unreviewed
CVE-2025-12414
was published
Nov 20, 2025
Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and...
Low
Unreviewed
CVE-2025-13015
was published
Nov 11, 2025
Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin...
Critical
Unreviewed
CVE-2025-58595
was published
Nov 6, 2025
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54...
High
Unreviewed
CVE-2025-11209
was published
Nov 7, 2025
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker...
High
Unreviewed
CVE-2025-12430
was published
Nov 10, 2025
An issue was discovered in AnyDesk through 9.0.4. When the connection between two clients is...
High
Unreviewed
CVE-2025-27916
was published
Nov 6, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
An inconsistent user interface issue was addressed with improved state management. This issue is...
Moderate
Unreviewed
CVE-2025-43503
was published
Nov 4, 2025
The issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1,...
Moderate
Unreviewed
CVE-2025-43493
was published
Nov 4, 2025
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a...
Moderate
Unreviewed
CVE-2024-34397
was published
May 7, 2024
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Shared Asset Booking...
Moderate
Unreviewed
CVE-2023-51323
was published
Feb 20, 2025
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software...
Moderate
Unreviewed
CVE-2023-51327
was published
Feb 20, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS...
Moderate
Unreviewed
CVE-2023-42889
was published
Feb 21, 2024
ProTip!
Advisories are also available from the
GraphQL API