GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,124
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
784 advisories
Filter by severity
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6...
High
Unreviewed
CVE-2023-0805
was published
May 4, 2023
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or...
High
Unreviewed
CVE-2025-26378
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less...
High
Unreviewed
CVE-2025-26372
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less...
High
Unreviewed
CVE-2025-26369
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or...
High
Unreviewed
CVE-2025-26377
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or...
High
Unreviewed
CVE-2025-26375
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less...
High
Unreviewed
CVE-2025-26371
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less...
High
Unreviewed
CVE-2025-26368
was published
Feb 12, 2025
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less...
High
Unreviewed
CVE-2025-26370
was published
Feb 12, 2025
The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that...
High
Unreviewed
CVE-2024-12296
was published
Feb 12, 2025
The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13653
was published
Feb 12, 2025
The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can...
High
Unreviewed
CVE-2024-13800
was published
Feb 12, 2025
The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13654
was published
Feb 12, 2025
The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13656
was published
Feb 12, 2025
The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13643
was published
Feb 11, 2025
Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows...
High
Unreviewed
CVE-2025-25167
was published
Feb 7, 2025
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin...
High
Unreviewed
CVE-2024-2782
was published
May 18, 2024
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an...
High
Unreviewed
CVE-2024-49742
was published
Jan 22, 2025
Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege...
High
Unreviewed
CVE-2023-51479
was published
May 17, 2024
The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post...
High
Unreviewed
CVE-2024-11601
was published
Nov 22, 2024
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n...
High
Unreviewed
CVE-2024-24832
was published
Mar 23, 2024
Incorrect access control in Geovision GV-ASWeb version 6.1.0.0 or less allows unauthorized...
High
Unreviewed
CVE-2024-56898
was published
Feb 3, 2025
Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue...
High
Unreviewed
CVE-2024-32682
was published
Apr 22, 2024
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15...
High
Unreviewed
CVE-2024-46450
was published
Jan 17, 2025
Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a...
High
Unreviewed
CVE-2024-33912
was published
May 6, 2024
ProTip!
Advisories are also available from the
GraphQL API