GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,877
Erlang
37
GitHub Actions
38
Go
2,538
Maven
5,000+
npm
4,197
NuGet
743
pip
3,971
Pub
12
RubyGems
947
Rust
1,030
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,091 advisories
Filter by severity
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
Missing Authorization vulnerability in shinetheme Traveler allows Exploiting Incorrectly...
High
Unreviewed
CVE-2025-59011
was published
Sep 26, 2025
Ericsson
Indoor Connect 8855 contains a missing authorization vulnerability which if
exploited...
High
Unreviewed
CVE-2025-40837
was published
Sep 25, 2025
An authorization bypass vulnerability has been discovered in the Click Plus C2-03CPU2 device...
High
Unreviewed
CVE-2025-55038
was published
Sep 24, 2025
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform...
High
Unreviewed
CVE-2025-57605
was published
Sep 22, 2025
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege...
High
Unreviewed
CVE-2025-7665
was published
Sep 19, 2025
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages...
High
Unreviewed
CVE-2025-8565
was published
Sep 18, 2025
Permission control vulnerability in the App Multiplier module
Impact:Successful exploitation of...
High
Unreviewed
CVE-2024-42035
was published
Aug 8, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2025-43286
was published
Sep 16, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in watchOS 26...
High
Unreviewed
CVE-2025-43329
was published
Sep 16, 2025
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in...
High
Unreviewed
CVE-2025-43358
was published
Sep 16, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2025-43316
was published
Sep 16, 2025
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2025-43341
was published
Sep 16, 2025
Flowise has unsandboxed remote code execution via Custom MCP
High
GHSA-6933-jpx5-q87q
was published
for
flowise
(npm)
Sep 15, 2025
Fides Webserver API is Vulnerable to OAuth Client Privilege Escalation
High
CVE-2025-57817
was published
for
ethyca-fides
(pip)
Sep 8, 2025
The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data...
High
Unreviewed
CVE-2025-9018
was published
Sep 11, 2025
The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that...
High
Unreviewed
CVE-2025-8425
was published
Sep 11, 2025
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2025-10040
was published
Sep 10, 2025
Missing authorization in the installer for Zoom Workplace for Windows on ARM before version 6.5.0...
High
Unreviewed
CVE-2025-49459
was published
Sep 10, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55141
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55142
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55148
was published
Sep 9, 2025
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure...
High
Unreviewed
CVE-2025-55145
was published
Sep 9, 2025
Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections...
High
Unreviewed
CVE-2024-36326
was published
Sep 6, 2025
The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to...
High
Unreviewed
CVE-2025-7040
was published
Sep 6, 2025
ProTip!
Advisories are also available from the
GraphQL API