GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,674 advisories
Filter by severity
A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an...
Moderate
Unreviewed
CVE-2025-14582
was published
Dec 13, 2025
A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown...
Moderate
Unreviewed
CVE-2025-14583
was published
Dec 13, 2025
Plesk 18.0 has Incorrect Access Control.
Critical
Unreviewed
CVE-2025-66430
was published
Dec 12, 2025
Improper access control in Windows Admin Center allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-64669
was published
Dec 11, 2025
A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The...
Moderate
Unreviewed
CVE-2025-14530
was published
Dec 11, 2025
A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The...
Moderate
Unreviewed
CVE-2025-14522
was published
Dec 11, 2025
Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
Low
CVE-2025-14082
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
Moderate
Unreviewed
CVE-2025-64897
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access...
High
Unreviewed
CVE-2025-61811
was published
Dec 10, 2025
Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges...
High
Unreviewed
CVE-2025-64673
was published
Dec 9, 2025
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an...
High
Unreviewed
CVE-2025-65594
was published
Dec 9, 2025
Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to...
High
Unreviewed
CVE-2025-62570
was published
Dec 9, 2025
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2,...
Moderate
Unreviewed
CVE-2025-59810
was published
Dec 9, 2025
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker...
High
Unreviewed
CVE-2025-62474
was published
Dec 9, 2025
An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.4,...
Low
Unreviewed
CVE-2025-59923
was published
Dec 9, 2025
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate...
High
Unreviewed
CVE-2025-59517
was published
Dec 9, 2025
An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction...
Moderate
Unreviewed
CVE-2025-63739
was published
Dec 9, 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected...
Moderate
Unreviewed
CVE-2025-40939
was published
Dec 9, 2025
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Critical
CVE-2025-67510
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
memos vulnerability allows arbitrarily modification or deletion registered identity providers
Moderate
CVE-2025-65797
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows the creation of arbitrary accounts
High
CVE-2025-65795
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily reactions deletion
Moderate
CVE-2025-65796
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
memos vulnerability allows arbitrarily modification or deletion of attachments
Moderate
CVE-2025-65798
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted...
Moderate
Unreviewed
CVE-2025-14219
was published
Dec 8, 2025
A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file...
Moderate
Unreviewed
CVE-2025-14199
was published
Dec 7, 2025
ProTip!
Advisories are also available from the
GraphQL API