GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
155 advisories
Filter by severity
Mattermost has an Incorrect Authorization vulnerability
Low
CVE-2025-10545
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long...
Low
Unreviewed
CVE-2025-59451
was published
Oct 6, 2025
A regular Zabbix user can search other users in their user group via Zabbix API by select fields...
Low
Unreviewed
CVE-2025-27236
was published
Oct 3, 2025
Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to...
Low
Unreviewed
CVE-2025-11239
was published
Oct 2, 2025
Omni Wireguard SideroLink potential escape
Low
CVE-2025-59824
was published
for
github.com/siderolabs/omni
(Go)
Sep 24, 2025
Liferay Portal JSON Web Services Direct Class Invocation Enables Service Access Policy Execution
Low
CVE-2025-43789
was published
for
com.liferay:com.liferay.comment.web
(Maven)
Sep 12, 2025
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability...
Low
Unreviewed
CVE-2025-7974
was published
Sep 2, 2025
Mattermost Lack of Access Control Validation
Low
CVE-2025-49810
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Properly Validate Team Role Modification
Low
CVE-2025-53971
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that...
Low
Unreviewed
CVE-2025-30750
was published
Jul 15, 2025
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1...
Low
Unreviewed
CVE-2025-6168
was published
Jul 10, 2025
An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1...
Low
Unreviewed
CVE-2025-4972
was published
Jul 10, 2025
Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2025-0885
was published
Jul 3, 2025
Sudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the...
Low
Unreviewed
CVE-2025-32462
was published
Jun 30, 2025
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected...
Low
Unreviewed
CVE-2025-49549
was published
Jun 26, 2025
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
Low
CVE-2025-4563
was published
for
k8s.io/kubernetes
(Go)
Jun 23, 2025
Mattermost allows guest users to view information about public teams they are not members of
Low
CVE-2025-4128
was published
for
github.com/mattermost/mattermost-server
(Go)
Jun 11, 2025
Mattermost fails to properly enforce access control restrictions for System Manager roles
Low
CVE-2025-3611
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
Mattermost fails to properly enforce access controls for guest users
Low
CVE-2025-1792
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 30, 2025
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In...
Low
Unreviewed
CVE-2025-1110
was published
May 22, 2025
TYPO3 Allows Information Disclosure via DBAL Restriction Handling
Low
CVE-2025-47937
was published
for
typo3/cms-core
(Composer)
May 20, 2025
Mattermost Fails to Check User Access to `ExperimentalSettings`
Low
CVE-2025-2570
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
May 15, 2025
An authenticated administrator could modify the Created By username for a user account
Low
Unreviewed
CVE-2025-46744
was published
May 12, 2025
Solr script service doesn't take dropped programming right into account
Low
CVE-2025-32971
was published
for
org.xwiki.platform:xwiki-platform-search-solr-api
(Maven)
Apr 29, 2025
Mattermost Playbooks fails to properly validate permissions
Low
CVE-2025-41423
was published
for
github.com/mattermost/mattermost-plugin-playbooks
(Go)
Apr 24, 2025
ProTip!
Advisories are also available from the
GraphQL API