GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
427 advisories
Filter by severity
Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a...
Moderate
Unreviewed
CVE-2025-13636
was published
Dec 2, 2025
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local...
Moderate
Unreviewed
CVE-2025-13635
was published
Dec 2, 2025
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41...
Moderate
Unreviewed
CVE-2025-13634
was published
Dec 2, 2025
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18...
Moderate
Unreviewed
CVE-2025-12653
was published
Nov 26, 2025
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Moderate
CVE-2025-63700
was published
for
@clerk/clerk-js
(npm)
Nov 20, 2025
An attacker could take over a Looker account in a Looker instance configured with OIDC...
Critical
Unreviewed
CVE-2025-12414
was published
Nov 20, 2025
Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and...
Low
Unreviewed
CVE-2025-13015
was published
Nov 11, 2025
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker...
High
Unreviewed
CVE-2025-12430
was published
Nov 10, 2025
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54...
High
Unreviewed
CVE-2025-11209
was published
Nov 7, 2025
An issue was discovered in AnyDesk through 9.0.4. When the connection between two clients is...
High
Unreviewed
CVE-2025-27916
was published
Nov 6, 2025
Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin...
Critical
Unreviewed
CVE-2025-58595
was published
Nov 6, 2025
The issue was addressed with improved checks. This issue is fixed in iOS 26.1 and iPadOS 26.1,...
Moderate
Unreviewed
CVE-2025-43493
was published
Nov 4, 2025
An inconsistent user interface issue was addressed with improved state management. This issue is...
Moderate
Unreviewed
CVE-2025-43503
was published
Nov 4, 2025
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized...
Moderate
Unreviewed
CVE-2025-59501
was published
Oct 31, 2025
Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On...
High
Unreviewed
CVE-2025-11843
was published
Oct 31, 2025
An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products...
Moderate
Unreviewed
CVE-2025-5605
was published
Oct 24, 2025
Reolink desktop application 8.18.12 contains a vulnerability in its local authentication...
Moderate
Unreviewed
CVE-2025-56800
was published
Oct 21, 2025
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to...
High
Unreviewed
CVE-2025-37147
was published
Oct 14, 2025
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
Moderate
CVE-2025-60868
was published
for
alt-design/alt-redirect
(Composer)
Oct 10, 2025
Python Social Auth - Django has unsafe account association
Moderate
CVE-2025-61783
was published
for
social-auth-app-django
(pip)
Oct 9, 2025
Akka.Remote TLS did not properly implement certificate-based authentication
Critical
CVE-2025-61778
was published
for
Akka.Cluster
(NuGet)
Oct 7, 2025
Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Moderate
CVE-2025-54288
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Coder AgentAPI exposed user chat history via a DNS rebinding attack
Moderate
CVE-2025-59956
was published
for
github.com/coder/agentapi
(Go)
Sep 29, 2025
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an...
High
Unreviewed
CVE-2025-56449
was published
Sep 29, 2025
This vulnerability affects Firefox < 143 and Thunderbird < 143.
Moderate
Unreviewed
CVE-2025-10530
was published
Sep 16, 2025
ProTip!
Advisories are also available from the
GraphQL API