GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
40
Go
2,974
Maven
5,000+
npm
4,621
NuGet
788
pip
4,317
Pub
12
RubyGems
984
Rust
1,131
Swift
49
Unreviewed advisories
All unreviewed
5,000+
815 advisories
Filter by severity
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2026-20666
was published
Feb 12, 2026
An authorization issue was addressed with improved state management. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2025-43403
was published
Feb 12, 2026
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before...
High
Unreviewed
CVE-2024-50617
was published
Feb 12, 2026
Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within...
Moderate
Unreviewed
CVE-2025-30508
was published
Feb 10, 2026
Claude Code has Permission Deny Bypass Through Symbolic Links
Low
CVE-2026-25724
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Critical
CVE-2026-25893
was published
for
fuxa-server
(npm)
Feb 5, 2026
It was identified that under certain specific preconditions, an API key that was originally...
Critical
Unreviewed
CVE-2024-37282
was published
Jan 30, 2026
The web interface offers a functionality to export the internal SQLite database. After executing...
Moderate
Unreviewed
CVE-2025-59100
was published
Jan 26, 2026
phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)
Moderate
CVE-2026-24421
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
Azure Entra ID Elevation of Privilege Vulnerability
Critical
Unreviewed
CVE-2026-24305
was published
Jan 23, 2026
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
High
CVE-2026-22022
was published
for
org.apache.solr:solr-core
(Maven)
Jan 21, 2026
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass...
High
Unreviewed
CVE-2026-21641
was published
Jan 20, 2026
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and...
Moderate
Unreviewed
CVE-2025-14348
was published
Jan 20, 2026
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over...
High
Unreviewed
CVE-2026-20960
was published
Jan 17, 2026
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed...
Moderate
Unreviewed
CVE-2026-22641
was published
Jan 15, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
High
CVE-2026-22033
was published
for
label-studio
(pip)
Jan 12, 2026
RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation
Moderate
CVE-2026-22042
was published
for
rustfs
(Rust)
Jan 8, 2026
A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the...
Moderate
Unreviewed
CVE-2025-67603
was published
Jan 8, 2026
The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized...
Low
Unreviewed
CVE-2025-12958
was published
Jan 7, 2026
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-9294
was published
Jan 6, 2026
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO
Moderate
CVE-2025-68481
was published
for
fastapi-users
(pip)
Dec 19, 2025
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation
Moderate
CVE-2025-14546
was published
for
fastapi-sso
(pip)
Dec 19, 2025
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate...
Critical
Unreviewed
CVE-2025-65041
was published
Dec 19, 2025
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator...
Moderate
Unreviewed
CVE-2025-46296
was published
Dec 16, 2025
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers...
Critical
Unreviewed
CVE-2023-53895
was published
Dec 16, 2025
ProTip!
Advisories are also available from the
GraphQL API