GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
331 advisories
Filter by severity
pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability
High
CVE-2025-9636
was published
for
pgadmin4
(pip)
Sep 5, 2025
Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue...
High
Unreviewed
CVE-2024-13068
was published
Sep 3, 2025
An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client...
High
Unreviewed
CVE-2025-51605
was published
Aug 22, 2025
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
'Same-origin policy bypass in the Graphics: Canvas2D component.' This vulnerability affects...
High
Unreviewed
CVE-2025-9180
was published
Aug 19, 2025
HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP...
Moderate
Unreviewed
CVE-2025-52621
was published
Aug 16, 2025
In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic...
Moderate
Unreviewed
CVE-2025-53399
was published
Aug 1, 2025
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
Duplicate Advisory: Keycloak phishing attack via email verification step in first login flow
Moderate
GHSA-gj52-35xm-gxjh
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 10, 2025
•
withdrawn
Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab...
High
Unreviewed
CVE-2025-53600
was published
Jul 4, 2025
Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass...
Moderate
Unreviewed
CVE-2025-5824
was published
Jun 26, 2025
The security settings in the SAP Business One Integration Framework are not adequately checked,...
Moderate
Unreviewed
CVE-2025-42998
was published
Jun 10, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Moderate
CVE-2025-30360
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may...
High
Unreviewed
CVE-2024-31127
was published
Jun 4, 2025
This issue was addressed through improved state management. This issue is fixed in Safari 18.4,...
Critical
Unreviewed
CVE-2025-30466
was published
May 30, 2025
Error handling for script execution was incorrectly isolated from web content, which could have...
Moderate
Unreviewed
CVE-2025-5263
was published
May 27, 2025
A vulnerability has been found in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3 and classified as...
Low
Unreviewed
CVE-2025-4839
was published
May 18, 2025
SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS)...
High
Unreviewed
CVE-2025-46737
was published
May 12, 2025
A vulnerability, which was classified as problematic, has been found in Freeebird Hotel 酒店管理系统...
Low
Unreviewed
CVE-2025-4542
was published
May 11, 2025
A vulnerability, which was classified as problematic, was found in Zylon PrivateGPT up to 0.6.2....
Moderate
Unreviewed
CVE-2025-4515
was published
May 10, 2025
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other...
High
Unreviewed
CVE-2025-3462
was published
May 9, 2025
@misskey-dev/summaly allows IP Filter Bypass via Redirect
Moderate
GHSA-jqx4-9gpq-rppm
was published
for
@misskey-dev/summaly
(npm)
May 6, 2025
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local...
Moderate
Unreviewed
CVE-2025-43929
was published
Apr 20, 2025
Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below...
Critical
Unreviewed
CVE-2025-3651
was published
Apr 17, 2025
Inappropriate implementation in Navigations in Google Chrome prior to 135.0.7049.52 allowed a...
Moderate
Unreviewed
CVE-2025-3071
was published
Apr 2, 2025
ProTip!
Advisories are also available from the
GraphQL API