GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,890
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,217
NuGet
745
pip
3,994
Pub
12
RubyGems
950
Rust
1,038
Swift
45
Unreviewed advisories
All unreviewed
5,000+
82 advisories
Filter by severity
Liferay Portal Vulnerable to IDOR via audit events
Moderate
CVE-2025-43827
was published
for
com.liferay:com.liferay.portal.security.audit.storage.service
(Maven)
Sep 30, 2025
Liferay Portal and DXP allows users to add a note to a different virtual instance
Moderate
CVE-2025-43810
was published
for
com.liferay.commerce:com.liferay.commerce.service
(Maven)
Sep 23, 2025
Liferay Contacts Center widget has insecure direct object reference
Moderate
CVE-2025-43803
was published
for
com.liferay:com.liferay.contacts.web
(Maven)
Sep 19, 2025
Liferay Portal API Allows Authenticated Users to Access Workflow Definitions by Name
Moderate
CVE-2025-43782
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.runtime.integration.impl
(Maven)
Sep 11, 2025
Indico may disclose unauthorized user details access via legacy API
Moderate
CVE-2025-59034
was published
for
indico
(pip)
Sep 10, 2025
Liferay Portal Vulnerable to Insecure Direct Object Reference
Moderate
CVE-2025-43732
was published
for
com.liferay:com.liferay.roles.selector.web
(Maven)
Aug 18, 2025
Indico vulnerability allows attackers to bulk dump user details
Moderate
CVE-2025-53640
was published
for
indico
(pip)
Jul 14, 2025
Femanager extension for TYPO3 allows Insecure Direct Object Reference
Moderate
CVE-2025-7900
was published
for
in2code/femanager
(Composer)
Jul 22, 2025
Powermail extension for TYPO3 allows Insecure Direct Object Reference
Moderate
CVE-2025-7899
was published
for
in2code/powermail
(Composer)
Jul 22, 2025
Grokability Snipe-IT has incorrect authorization for accessing asset information
Moderate
CVE-2025-47226
was published
for
snipe/snipe-it
(Composer)
May 2, 2025
Security Update for the OPC UA .NET Standard Stack
Moderate
CVE-2024-42512
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
Mar 3, 2025
reint_downloadmanager TYPO3 Extension is susceptible to Insecure Direct Object Reference
Moderate
CVE-2025-48207
was published
for
renolit/reint-downloadmanager
(Composer)
May 21, 2025
The femanager TYPO3 extension allows Insecure Direct Object Reference
Moderate
CVE-2025-48202
was published
for
in2code/femanager
(Composer)
May 21, 2025
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
Moderate
CVE-2025-3640
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
Moderate
CVE-2025-3636
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Moderate
CVE-2022-31683
was published
for
github.com/concourse/concourse
(Go)
Oct 19, 2022
events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability
Moderate
CVE-2024-38874
was published
for
jweiland/events2
(Composer)
Jun 21, 2024
Directus has an insecure object reference via PATH presets
Moderate
CVE-2024-6534
was published
for
directus
(npm)
Aug 27, 2024
Duplicate Advisory: Improper access control in Directus
Moderate
GHSA-q83v-hq3j-4pq3
was published
for
directus
(npm)
Aug 15, 2024
•
withdrawn
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
IDOR vulnerability in account profile page
Moderate
CVE-2024-39319
was published
for
aimeos/ai-controller-frontend
(Composer)
Sep 26, 2024
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-38218
was published
for
magento/community-edition
(Composer)
Oct 13, 2023
Magento Insecure Direct Object Reference (IDOR) in the product module
Moderate
CVE-2021-21022
was published
for
magento/community-edition
(Composer)
May 24, 2022
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
Moderate
CVE-2024-38827
was published
for
org.springframework.security:spring-security-core
(Maven)
Dec 2, 2024
Authorization Bypass in moodle
Moderate
CVE-2024-25983
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
ProTip!
Advisories are also available from the
GraphQL API